External risk intelligence

Waterfall WF-500 OS Command Injection in Console WebUI

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-41272

The vulnerability involves unauthenticated OS command injection in a network appliance web interface. As the attack vector is network-based with low attack complexity and no authentication required, the surface is highly exposed if the management interface is reachable over the network.

OS Command Injection

Waterfall Security Wf 500 Firmware

7.9.1.0_r2502171040 and earlier

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Waterfall WF-500 TX and RX Hosts, specifically within the Console WebUI. This flaw allows unauthenticated attackers to remotely execute arbitrary operating system commands, potentially impacting device control and integrity. The main concern is confirming the relevance and exposure of this technology within our environment.

  • Remote attackers can run any command.
  • Critical for network appliance security.
  • Verify if this device is in use.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can reach the vulnerable component through the network by interacting with the Console WebUI. This interaction allows the attacker to inject operating system commands, potentially leading to full device compromise.

  • Entry: Network access to Console WebUI.
  • Trigger: Injecting commands into the WebUI.
  • Risk: Arbitrary command execution on the device.

Live Threat

Current exploitation, exposure, and threat context

A critical vulnerability exists in the Console WebUI of Waterfall WF-500 TX and RX Hosts, allowing remote, unauthenticated attackers to execute arbitrary operating system commands. This could impact the integrity and availability of the device when its management interface is accessible over the network.

  • Device operating system and configuration data.
  • Remote, unauthenticated command injection.
  • Compromised device integrity and availability.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Waterfall WF-500 hosts' Console WebUI is susceptible to OS command injection, allowing unauthenticated remote attackers to execute arbitrary commands. Ownership of this issue likely falls to the team managing the Waterfall devices, which could be an industrial control systems (ICS) or operational technology (OT) security team, or an infrastructure team responsible for network appliances. The first practical step is to identify all WF-500 devices, confirm their network exposure and business criticality, and then engage the accountable owner to plan remediation, potentially involving vendor coordination.

  • Waterfall device owners should lead.
  • Confirm network exposure and criticality.
  • Plan vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Waterfall WF-500?

The Waterfall WF-500 is a specialized network appliance, specifically TX and RX hosts, designed to facilitate secure data transfers in industrial environments. These devices act as a one-way security gateway or data diode, maintaining network separation by ensuring information flows in only one direction. They are typically deployed to protect sensitive operational technology (OT) networks from external threats by preventing bidirectional communication.

What does CWE-78 mean for CVE-2025-41272?

CWE-78, or OS Command Injection, occurs when an application fails to properly sanitize user input before passing it to a system shell. In this case, the Console WebUI of the device accepts malicious input as if it were a legitimate command. Because the interface does not neutralize these special characters, an attacker can trick the system into running unauthorized commands at the operating system level, effectively gaining control over the device's functions.

How is this OS command injection triggered?

An attacker triggers this vulnerability by sending specifically crafted requests to the Console WebUI of a Waterfall WF-500 host. Because the flaw exists in the web interface, the attacker does not need a valid user account or password to interact with it. Note that simply having the device powered on or connected to an internal network does not trigger the bug; the attacker must be able to reach the Console WebUI over the network and interact with it via these malicious commands.

How relevant is this CVE based on Halo Surface Signal?

According to Halo Surface Signal, this vulnerability is highly relevant if your Waterfall WF-500 Console WebUI is reachable over the network. Because the vulnerability requires no authentication and has low attack complexity, any management interface exposed to an untrusted network, such as the public internet, is at significant risk. Organizations should prioritize checking whether these interfaces are accessible to unauthorized users or outside the local network perimeter.

What should I do if I manage Waterfall devices?

Your first step is to create a complete inventory of all Waterfall WF-500 devices within your infrastructure. Once identified, verify their network configuration to determine if the Console WebUI is exposed to broader network segments. You should then coordinate with your internal security team or the vendor to understand the recommended path for updates or configuration changes, ensuring that the management interface is restricted to authorized administrative segments only.

References