CVE-2025-41280: Path Traversal
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured and file compression is enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41280?
CVE-2025-41280 has a high severity rating of 7.5 based on CVSS 4.0.
How do I fix CVE-2025-41280?
To mitigate CVE-2025-41280, ensure that the MySQL connector is correctly configured and file compression is disabled on the Waterfall WF-500 RX Host.
What is the impact of CVE-2025-41280?
CVE-2025-41280 allows attackers with access to the TX Host to execute code on the RX Host, leading to potential unauthorized access.
Which software is affected by CVE-2025-41280?
CVE-2025-41280 affects the Nozomi Networks Waterfall WF-500 RX Host version 7.9.1.0 R2502171040.
When was CVE-2025-41280 published?
CVE-2025-41280 was published on May 29, 2026.