CVE-2025-41268: Path Traversal
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete arbitrary files on the Host machines.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nozomi Networks Waterfall WF-500 TX and RX Administration WebUIto a version that resolves this vulnerability.Fixed in 7.9.1.0 R2502171040
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41268?
The severity of CVE-2025-41268 is high, with a CVSS score of 8.8.
How do I fix CVE-2025-41268?
To fix CVE-2025-41268, update your Waterfall WF-500 TX or RX Hosts to version 7.9.1.0 R2502171040 or later.
What type of vulnerability is CVE-2025-41268?
CVE-2025-41268 is classified as a CWE-23: Relative Path Traversal vulnerability.
Who is affected by CVE-2025-41268?
CVE-2025-41268 affects users of Waterfall Security WF-500 TX and RX Hosts running version 7.9.1.0 R2502171040.
What can attackers do with CVE-2025-41268?
Attackers exploiting CVE-2025-41268 can delete arbitrary files on the Host machines without authentication.