CVE-2025-41265: OS Command Injection
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 TX Host.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41265?
The severity of CVE-2025-41265 is rated high with a score of 8.6.
How do I fix CVE-2025-41265?
To fix CVE-2025-41265, upgrade to the latest version of Waterfall WF-500 TX Host that addresses this vulnerability.
What types of attacks are possible with CVE-2025-41265?
CVE-2025-41265 allows remote authenticated attackers to perform OS command injection, enabling them to execute arbitrary operating system commands.
Which software is affected by CVE-2025-41265?
CVE-2025-41265 affects the Waterfall WF-500 TX Host running version 7.9.1.0 R2502171040.
What is the Vector Impact of CVE-2025-41265?
CVE-2025-41265 has a Vector Impact of high severity due to potential complete system compromise through OS command injection.