Aller au contenu

Fiche vulnérabilité

CVE-2025-41269 : faille critique waterfall-security wf-500 firmware (CVSS 9.8)

Description

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
29 mai 2026
Dernière mise à jour
21 juil. 2026

Produits concernés

  • waterfall-security wf-500 firmware

Références

Rechercher une autre vulnérabilité dans la base CVE