Skip to content
COOEY

EXPOSURES › CVE-2025-41268

CVE-2025-41268

CRITICAL
DETAIL
SourceNVD · cve Published2026-05-29 CVSS9.1 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-41268 ↗

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete arbitrary files on the Host machines.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Security Service Edge (Formerly McAfee MVISION)
Skyhigh Security
Authorized