CVE-2025-41275: OS Command Injection
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41275?
CVE-2025-41275 has a critical severity rating of 9.3.
How do I fix CVE-2025-41275?
To fix CVE-2025-41275, update the Waterfall WF-500 TX and RX Hosts to a version that addresses the OS command injection vulnerability.
What vulnerability does CVE-2025-41275 exploit?
CVE-2025-41275 exploits an OS command injection vulnerability due to improper neutralization of special elements in the Console WebUI.
Who is affected by CVE-2025-41275?
Users of Nozomi Networks Waterfall WF-500 TX and RX Hosts running version 7.9.1.0 R2502171040 are affected by CVE-2025-41275.
What are the potential consequences of CVE-2025-41275?
CVE-2025-41275 allows remote unauthenticated attackers to execute arbitrary operating system commands, potentially leading to severe security breaches.