CVE-2025-41271: Path Traversal
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to read arbitrary files from the device.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Waterfall WF-500 TX and RX Hoststo a version that resolves this vulnerability.Fixed in 7.9.1.0 R2502171040
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41271?
CVE-2025-41271 has a severity rating of high, with a CVSS score of 8.7.
What type of vulnerability is CVE-2025-41271?
CVE-2025-41271 is a relative path traversal vulnerability identified as CWE-23.
How does CVE-2025-41271 affect users?
CVE-2025-41271 allows remote unauthenticated attackers to read arbitrary files from the affected device.
Which versions are affected by CVE-2025-41271?
CVE-2025-41271 affects Nozomi Networks Waterfall WF-500 TX and RX Hosts running version 7.9.1.0 R2502171040.
How do I fix CVE-2025-41271?
To fix CVE-2025-41271, update to the latest version of Nozomi Networks Waterfall software that addresses this vulnerability.