CVE-2025-41281: OS Command Injection
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Waterfall WF-500 RX Hostto a version that resolves this vulnerability.Fixed in 7.9.1.0Patch R2502171040
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41281?
CVE-2025-41281 has a severity rating of high with a CVSS score of 7.5.
How can I fix CVE-2025-41281?
To mitigate CVE-2025-41281, upgrade the Waterfall WF-500 RX Host to version 7.9.1.0 R2502171041 or later.
What does CVE-2025-41281 exploit?
CVE-2025-41281 exploits improper neutralization of special elements used in an OS command, allowing OS command injection.
What software is affected by CVE-2025-41281?
The affected software is the Nozomi Networks Waterfall WF-500 RX Host, specifically version 7.9.1.0 R2502171040.
Who discovered CVE-2025-41281?
CVE-2025-41281 was identified by Nozomi Networks Labs.