EXPOSURES › CVE-2025-41269
CVE-2025-41269
CRITICAL
DETAIL
SourceNVD · cve
Published2026-05-29
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-41269 ↗
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
DESCRIPTION
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.
AFFECTED FEDRAMP PRODUCTS · 1
| PRODUCT | STATUS |
|---|---|
| Security Service Edge (Formerly McAfee MVISION) Skyhigh Security |
Authorized |