CVE-2025-41281

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:waterfall-security:wf-500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:waterfall-security:wf-500:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-29 12:16

Updated : 2026-07-21 12:10


NVD link : CVE-2025-41281

Mitre link : CVE-2025-41281

CVE.ORG link : CVE-2025-41281


JSON object : View

Products Affected

waterfall-security

  • wf-500
  • wf-500_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')