CVE-2025-41270
A critical OS command injection flaw in the Console WebUI of Waterfall WF-500 TX and RX Hosts allows remote attackers to run arbitrary operating system commands. The vulnerability exists in firmware version 7.9.1.0 R2502171040. It could give attackers full control over the device.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Waterfall WF-500 TX and RX Hosts running firmware 7.9.1.0 R2502171040 (CPE: waterfall-security wf-500_firmware).
Real-world impact
An attacker could execute any command on the device, potentially taking full control, exfiltrating data, or disrupting services.
Why this severity
The CVSS score of 9.3 reflects that the flaw is remotely exploitable without authentication or user interaction, and it provides complete system compromise.
What to do about it
- ›Restrict access to the Console WebUI to trusted networks only.
- ›Disable the WebUI if it is not required for operation.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- May 29, 2026 · May 29, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 14d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- nozominetworks.com/labs/vulnerability-advisori…vendor advisory