Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 01 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Waterfall-security
Waterfall-security wf-500 Waterfall-security wf-500 Firmware |
|
| CPEs | cpe:2.3:h:waterfall-security:wf-500:-:*:*:*:*:*:*:* cpe:2.3:o:waterfall-security:wf-500_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Waterfall-security
Waterfall-security wf-500 Waterfall-security wf-500 Firmware |
|
| Metrics |
cvssV3_1
|
Fri, 29 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Waterfall
Waterfall wf-500 |
|
| Vendors & Products |
Waterfall
Waterfall wf-500 |
Fri, 29 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OS Command Injection in Nozomi Networks Waterfall WF-500 RX Host Enables Remote Code Execution |
Fri, 29 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2026-05-29T13:36:44.165Z
Reserved: 2025-04-16T09:53:43.284Z
Link: CVE-2025-41281
Updated: 2026-05-29T13:36:40.719Z
Status : Analyzed
Published: 2026-05-29T12:16:24.670
Modified: 2026-06-01T18:55:43.283
Link: CVE-2025-41281
No data.
OpenCVE Enrichment
Updated: 2026-05-29T15:46:46Z