CVE-2025-41267: OS Command Injection
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 TX Host.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Waterfall WF-500 TX Hostto a version that resolves this vulnerability.Fixed in 7.9.1.0Patch R2502171040
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41267?
CVE-2025-41267 has a high severity rating of 8.5.
How do I fix CVE-2025-41267?
To mitigate CVE-2025-41267, it is recommended to update to the patched version of Waterfall Security WF-500 TX Host.
What type of vulnerability is CVE-2025-41267?
CVE-2025-41267 is categorized as an OS Command Injection vulnerability.
Who is affected by CVE-2025-41267?
CVE-2025-41267 affects users of the Waterfall Security WF-500 TX Host version 7.9.1.0 R2502171040.
Can CVE-2025-41267 be exploited remotely?
Yes, CVE-2025-41267 can be exploited by remote authenticated attackers.