CVE-2025-41268
Waterfall WF-500, wf-500 firmware, wf-500
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete arbitrary files on the Host machines.
- CVSS
- 8.8
- EPSS
- 0.44% 35.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.29