CVE-2025-41279: OS Command Injection
Published May 29, 2026
·Updated
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 RX Host.
Affected Software
3 affected components
Waterfall Security WF-500 RX Host=7.9.1.0 R2502171040
All of the following
Waterfall-security Wf-500 Firmware<=7.9.1.0_r2502171040
Waterfall-security Wf-500
Event History
May 29, 2026
CVE Published
via MITRE·10:59 AM
Data Sourced
via MITRE·10:59 AM
DescriptionWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-41279?
The severity of CVE-2025-41279 is high with a CVSS score of 8.6.
2
How do I fix CVE-2025-41279?
To fix CVE-2025-41279, upgrade the Waterfall WF-500 RX Host software to version 7.9.1.0 R2502171040 or later.
3
What type of vulnerability is CVE-2025-41279?
CVE-2025-41279 is an OS Command Injection vulnerability.
4
Who is affected by CVE-2025-41279?
Remote authenticated attackers can exploit CVE-2025-41279 on the Waterfall WF-500 RX Host.
5
When was CVE-2025-41279 published?
CVE-2025-41279 was published on May 29, 2026.