|
1
|
7.2 |
HIGH
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version…
Update
|
CWE-78
OS Command
|
CVE-2025-41265
|
2026-06-2 03:58 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2
|
7.2 |
HIGH
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version…
Update
|
CWE-78
OS Command
|
CVE-2025-41266
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3
|
7.2 |
HIGH
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version…
Update
|
CWE-78
OS Command
|
CVE-2025-41267
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4
|
9.1 |
CRITICAL
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated att…
Update
|
CWE-23
Relative Path Traversal
|
CVE-2025-41268
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5
|
9.8 |
CRITICAL
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in versio…
Update
|
CWE-78
OS Command
|
CVE-2025-41269
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6
|
9.8 |
CRITICAL
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in versio…
Update
|
CWE-78
OS Command
|
CVE-2025-41270
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7
|
7.5 |
HIGH
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers …
Update
|
CWE-23
Relative Path Traversal
|
CVE-2025-41271
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
8
|
9.8 |
CRITICAL
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in versio…
Update
|
CWE-78
OS Command
|
CVE-2025-41272
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
9
|
9.8 |
CRITICAL
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows…
Update
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2025-41273
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
10
|
9.8 |
CRITICAL
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in versio…
Update
|
CWE-78
OS Command
|
CVE-2025-41274
|
2026-06-2 03:56 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|