The number and severity of CVEs published that impact products developed by Waterfall Security over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-41272CRITICAL Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and | May 29, 2026 | 9.8 | 39 | NO | NO |
CVE-2025-41277CRITICAL Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and | May 29, 2026 | 9.8 | 38 | NO | NO |
CVE-2025-41276CRITICAL Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and | May 29, 2026 | 9.8 | 38 | NO | NO |
CVE-2025-41275CRITICAL Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and | May 29, 2026 | 9.8 | 38 | NO | NO |
CVE-2025-41274CRITICAL Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and | May 29, 2026 | 9.8 | 38 | NO | NO |
CVE-2025-41273CRITICAL Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R250 | May 29, 2026 | 9.8 | 38 | NO | NO |
CVE-2025-41270CRITICAL Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and | May 29, 2026 | 9.8 | 38 | NO | NO |
CVE-2025-41269CRITICAL Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and | May 29, 2026 | 9.8 | 38 | NO | NO |
CVE-2025-41268CRITICAL Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote | May 29, 2026 | 9.1 | 36 | NO | NO |
CVE-2025-41281HIGH Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 | May 29, 2026 | 7.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Waterfall Security.
Media articles that mention a CVE ID that affects a product developed by Waterfall Security — matched by CVE ID, not by vendor name.