EXPOSURES › CVE-2025-41268
CVE-2025-41268
CRITICAL
DETAIL
SourceNVD · cve
Published2026-05-29
CVSS9.1
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-41268 ↗
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
DESCRIPTION
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete arbitrary files on the Host machines.
AFFECTED FEDRAMP PRODUCTS · 1
| PRODUCT | STATUS |
|---|---|
| Security Service Edge (Formerly McAfee MVISION) Skyhigh Security |
Authorized |