Skip to content
COOEY

EXPOSURES › CVE-2025-41277

CVE-2025-41277

CRITICAL
DETAIL
SourceNVD · cve Published2026-05-29 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-41277 ↗

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Security Service Edge (Formerly McAfee MVISION)
Skyhigh Security
Authorized