PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-41268 Waterfall CVE debrief

A relative path traversal vulnerability (CWE-23) in the Administration WebUI of Waterfall WF-500 TX and RX Hosts allows remote unauthenticated attackers to delete arbitrary files on affected systems. The vulnerability exists in firmware version 7.9.1.0 R2502171040 and was identified by Nozomi Networks Labs. The CVSS 4.0 vector indicates network attack vector with low attack complexity, no privileges required, and no user interaction needed, with high impact to integrity and availability of the host system. The CVE was published on May 29, 2026 and last modified on June 1, 2026. No known exploitation in ransomware campaigns has been reported, and the vulnerability is not listed in CISA KEV.

Vendor
Waterfall
Product
WF-500
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-29
Original CVE updated
2026-06-01
Advisory published
2026-05-29
Advisory updated
2026-06-01

Who should care

Organizations deploying Waterfall WF-500 unidirectional security gateways in critical infrastructure environments, including electric utilities, oil and gas facilities, manufacturing plants, and other industrial control system deployments where operational technology network segmentation depends on Waterfall gateway integrity.

Technical summary

The Administration WebUI in Waterfall WF-500 TX and RX Hosts firmware version 7.9.1.0 R2502171040 fails to properly sanitize user-supplied file paths, allowing relative path traversal sequences to reach outside intended directories. A remote unauthenticated attacker can exploit this weakness to delete arbitrary files on the underlying host operating system. The vulnerability is reachable over the network without authentication credentials or user interaction. Successful exploitation results in high integrity and availability impact to the host system, with potential to disrupt unidirectional gateway operations or compromise system stability.

Defensive priority

HIGH

Recommended defensive actions

  • Restrict network access to Waterfall WF-500 Administration WebUI interfaces to authorized management hosts only
  • Apply vendor-provided firmware updates when available from Waterfall Security
  • Monitor for anomalous file deletion activity on WF-500 TX and RX Host systems
  • Review and validate input sanitization on all WebUI endpoints accepting file paths
  • Segment WF-500 management interfaces from operational technology networks per IEC 62443 zone and conduit guidance

Evidence notes

The vulnerability is classified as CWE-23 (Relative Path Traversal) per the primary weakness source from Nozomi Networks. CPE criteria confirm affected product as Waterfall Security WF-500 firmware up to and including version 7.9.1.0_r2502171040. The CVSS 4.0 score of 8.8 reflects HIGH severity with network accessibility and unauthenticated exploitation path.

Official resources

Nozomi Networks Labs disclosed this vulnerability via coordinated disclosure with a vendor advisory published to their security labs portal.