logo

CVE-2025-41280 | Waterfall WF-500 up to 7.9.1.0 R2502171040 File Compression path traversal

ID: ac654589-aa10-5244-940a-82ddf479dcb2

STIX ID: report--ac654589-aa10-5244-940a-82ddf479dcb2

Feed Name: VulDB Recent Entries

Threat Score
55/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: vuldb.com

...
...

A critical vulnerability (CVE-2025-41280) affecting Waterfall WF-500 (up to 7.9.1.0 R2502171040) is disclosed: a relative path traversal (Zip Slip) in the File Compression Handler that may allow attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured and file compression is enabled. CVSS meta/temp score is 7.8, exploitation requires local access, no exploit is currently available, and no concrete mitigations are documented.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.