PatchSiren cyber security CVE debrief
CVE-2025-41268 Waterfall CVE debrief
A relative path traversal vulnerability (CWE-23) in the Administration WebUI of Waterfall WF-500 TX and RX Hosts allows remote unauthenticated attackers to delete arbitrary files on affected systems. The vulnerability exists in firmware version 7.9.1.0 R2502171040 and was identified by Nozomi Networks Labs. The CVSS 4.0 vector indicates network attack vector with low attack complexity, no privileges required, and no user interaction needed, with high impact to integrity and availability of the host system. The CVE was published on May 29, 2026 and last modified on June 1, 2026. No known exploitation in ransomware campaigns has been reported, and the vulnerability is not listed in CISA KEV.
- Vendor
- Waterfall
- Product
- WF-500
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-29
- Original CVE updated
- 2026-06-01
- Advisory published
- 2026-05-29
- Advisory updated
- 2026-06-01
Who should care
Organizations deploying Waterfall WF-500 unidirectional security gateways in critical infrastructure environments, including electric utilities, oil and gas facilities, manufacturing plants, and other industrial control system deployments where operational technology network segmentation depends on Waterfall gateway integrity.
Technical summary
The Administration WebUI in Waterfall WF-500 TX and RX Hosts firmware version 7.9.1.0 R2502171040 fails to properly sanitize user-supplied file paths, allowing relative path traversal sequences to reach outside intended directories. A remote unauthenticated attacker can exploit this weakness to delete arbitrary files on the underlying host operating system. The vulnerability is reachable over the network without authentication credentials or user interaction. Successful exploitation results in high integrity and availability impact to the host system, with potential to disrupt unidirectional gateway operations or compromise system stability.
Defensive priority
HIGH
Recommended defensive actions
- Restrict network access to Waterfall WF-500 Administration WebUI interfaces to authorized management hosts only
- Apply vendor-provided firmware updates when available from Waterfall Security
- Monitor for anomalous file deletion activity on WF-500 TX and RX Host systems
- Review and validate input sanitization on all WebUI endpoints accepting file paths
- Segment WF-500 management interfaces from operational technology networks per IEC 62443 zone and conduit guidance
Evidence notes
The vulnerability is classified as CWE-23 (Relative Path Traversal) per the primary weakness source from Nozomi Networks. CPE criteria confirm affected product as Waterfall Security WF-500 firmware up to and including version 7.9.1.0_r2502171040. The CVSS 4.0 score of 8.8 reflects HIGH severity with network accessibility and unauthenticated exploitation path.
Official resources
-
CVE-2025-41268 CVE record
CVE.org
-
CVE-2025-41268 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
Nozomi Networks Labs disclosed this vulnerability via coordinated disclosure with a vendor advisory published to their security labs portal.