CVE-2025-41279
OS Command Injection in Waterfall WF-500 RX Host
Publication date: 2026-05-29
Last updated on: 2026-05-29
Assigner: Nozomi Networks Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nozomi_networks | waterfall_wf-500_rx_host | 7.9.1.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-78 | The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an OS Command Injection (CWE-78) found in the Administration WebUI of the Waterfall WF-500 RX Host version 7.9.1.0. It allows remote authenticated attackers to execute arbitrary operating system commands on the affected device.
How can this vulnerability impact me? :
The vulnerability allows remote authenticated attackers to run arbitrary OS commands on the WF-500 RX Host, which can lead to unauthorized control over the device, potential data compromise, disruption of services, or further exploitation within the network.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The provided information does not specify how this OS Command Injection vulnerability in the Waterfall WF-500 RX Host affects compliance with common standards and regulations such as GDPR or HIPAA.
What immediate steps should I take to mitigate this vulnerability?
The recommended immediate step to mitigate this vulnerability is to update the Waterfall WF-500 RX Host software to version 7.10.0.0 R2601141040.