CVE-2025-41266: OS Command Injection
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 TX Host.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Waterfall WF-500 TX Hostto a version that resolves this vulnerability.Fixed in 7.9.1.0Patch R2502171040
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41266?
CVE-2025-41266 has a severity score of 8.6, indicating a high risk.
How do I fix CVE-2025-41266?
To fix CVE-2025-41266, update to the patched version of Waterfall WF-500 TX Host that addresses the OS Command Injection vulnerability.
What kind of attack does CVE-2025-41266 allow?
CVE-2025-41266 allows remote authenticated attackers to execute arbitrary operating system commands.
Which versions of Waterfall are affected by CVE-2025-41266?
CVE-2025-41266 affects Waterfall WF-500 TX Host version 7.9.1.0 R2502171040.
What is the nature of the vulnerability in CVE-2025-41266?
CVE-2025-41266 is classified as an OS Command Injection vulnerability, specifically a CWE-78 issue.