Home/Product/waterfall security wf 500 firmware
Product

waterfall security wf 500 firmware

17 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-41281
<= 7.9.1.0_r2502171040
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection
7.8HIGH
CVE-2025-41280
<= 7.9.1.0_r2502171040
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R25021
7.8HIGH
CVE-2025-41279
<= 7.9.1.0_r2502171040
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection
7.2HIGH
CVE-2025-41278
<= 7.9.1.0_r2502171040
Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that all
7.8HIGH
CVE-2025-41277
<= 7.9.1.0_r2502171040
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection
9.8CRITICAL
CVE-2025-41276
<= 7.9.1.0_r2502171040
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection
9.8CRITICAL
CVE-2025-41275
<= 7.9.1.0_r2502171040
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection
9.8CRITICAL
CVE-2025-41274
<= 7.9.1.0_r2502171040
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection
9.8CRITICAL
CVE-2025-41273
<= 7.9.1.0_r2502171040
Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterf
9.8CRITICAL
CVE-2025-41272
<= 7.9.1.0_r2502171040
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection
9.8CRITICAL
CVE-2025-41271
<= 7.9.1.0_r2502171040
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in vers
7.5HIGH
CVE-2025-41270
<= 7.9.1.0_r2502171040
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection
9.8CRITICAL
CVE-2025-41269
<= 7.9.1.0_r2502171040
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection
9.8CRITICAL
CVE-2025-41268
<= 7.9.1.0_r2502171040
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts
9.1CRITICAL
CVE-2025-41267
<= 7.9.1.0_r2502171040
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection
7.2HIGH
CVE-2025-41266
<= 7.9.1.0_r2502171040
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection
7.2HIGH
CVE-2025-41265
<= 7.9.1.0_r2502171040
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection
7.2HIGH
threatengine.sh