CVE-2025-41272: OS Command Injection
Published May 29, 2026
·Updated
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.
Affected Software
4 affected components
Nozomi Networks Waterfall WF-500 TX Host=7.9.1.0 R2502171040
Nozomi Networks Waterfall WF-500 RX Host=7.9.1.0 R2502171040
All of the following
Waterfall-security Wf-500 Firmware<=7.9.1.0_r2502171040
Waterfall-security Wf-500
Event History
May 29, 2026
CVE Published
via MITRE·10:52 AM
Data Sourced
via MITRE·10:52 AM
DescriptionWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-41272?
CVE-2025-41272 has a critical severity rating of 9.3.
2
How do I fix CVE-2025-41272?
To fix CVE-2025-41272, update the Waterfall WF-500 TX and RX Hosts to the latest firmware version.
3
What type of vulnerability is CVE-2025-41272?
CVE-2025-41272 is categorized as an OS Command Injection vulnerability.
4
Who is affected by CVE-2025-41272?
CVE-2025-41272 affects users of Nozomi Networks Waterfall WF-500 TX and RX Host in version 7.9.1.0 R2502171040.
5
Can CVE-2025-41272 be exploited remotely?
Yes, CVE-2025-41272 can be exploited by remote unauthenticated attackers.