logo

CVE-2025-41277 | Waterfall WF-500 up to 7.9.1.0 R2502171040 Console WebUI os command injection

ID: 5b0a7729-a962-5d8c-8d08-2eefcc1e0d5f

STIX ID: report--5b0a7729-a962-5d8c-8d08-2eefcc1e0d5f

Feed Name: VulDB Recent Entries

Threat Score
75/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: vuldb.com

...
...

A critical OS command injection (CVE-2025-41277) was identified in the Console WebUI of Waterfall WF-500 devices up to version 7.9.1.0 (R2502171040), allowing remote unauthenticated attackers to execute arbitrary operating system commands; the issue is rated highly severe (VulDB/CVSS 9.8), was disclosed by Nozomi Networks Labs, and currently has no public exploit though exploitability is described as easy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.