waterfall-security records
17 published records for vendor waterfall-security.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')12
- CWE-23 Relative Path Traversal3
- CWE-125 Out-of-bounds Read1
- CWE-288 Authentication Bypass Using an Alternate Path or Channel1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2025-41274No exploit | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the waterfall-security · wf-500 firmware · CWE-78 | Critical9.3 | — | 1.4% | May 29, 2026 |
37Monitor | CVE-2025-41275No exploit | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the waterfall-security · wf-500 firmware · CWE-78 | Critical9.3 | — | 1.4% | May 29, 2026 |
37Monitor | CVE-2025-41276No exploit | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the waterfall-security · wf-500 firmware · CWE-78 | Critical9.3 | — | 1.4% | May 29, 2026 |
37Monitor | CVE-2025-41277No exploit | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the waterfall-security · wf-500 firmware · CWE-78 | Critical9.3 | — | 1.4% | May 29, 2026 |
37Monitor | CVE-2025-41272No exploit | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the waterfall-security · wf-500 firmware · CWE-78 | Critical9.3 | — | 1.4% | May 29, 2026 |
37Monitor | CVE-2025-41269No exploit | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the waterfall-security · wf-500 firmware · CWE-78 | Critical9.3 | — | 1.4% | May 29, 2026 |
37Monitor | CVE-2025-41270No exploit | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the waterfall-security · wf-500 firmware · CWE-78 | Critical9.3 | — | 1.4% | May 29, 2026 |
37Monitor | CVE-2025-41273No exploit | Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500waterfall-security · wf-500 firmware · CWE-288 | Critical9.3 | — | 0.4% | May 29, 2026 |
35Monitor | CVE-2025-41268No exploit | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in versionwaterfall-security · wf-500 firmware · CWE-23 | High8.8 | — | 0.4% | May 29, 2026 |
34Monitor | CVE-2025-41265No exploit | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the waterfall-security · wf-500 firmware · CWE-78 | High8.6 | — | 0.9% | May 29, 2026 |
34Monitor | CVE-2025-41266No exploit | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the waterfall-security · wf-500 firmware · CWE-78 | High8.6 | — | 0.9% | May 29, 2026 |
34Monitor | CVE-2025-41267No exploit | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the waterfall-security · wf-500 firmware · CWE-78 | High8.5 | — | 0.9% | May 29, 2026 |
34Monitor | CVE-2025-41279No exploit | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the waterfall-security · wf-500 firmware · CWE-78 | High8.6 | — | 0.9% | May 29, 2026 |
34Monitor | CVE-2025-41271No exploit | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.waterfall-security · wf-500 firmware · CWE-23 | High8.7 | — | 0.4% | May 29, 2026 |
30Monitor | CVE-2025-41281No exploit | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Watewaterfall-security · wf-500 firmware · CWE-78 | High7.5 | — | 0.5% | May 29, 2026 |
30Monitor | CVE-2025-41280No exploit | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 thatwaterfall-security · wf-500 firmware · CWE-23 | High7.5 | — | 0.1% | May 29, 2026 |
30Monitor | CVE-2025-41278No exploit | Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that allows attackwaterfall-security · wf-500 firmware · CWE-125 | High7.5 | — | 0.1% | May 29, 2026 |
- CVE-2025-4127437Monitor
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the
CriticalCVSS 9.3No exploitEPSS 1%waterfall-security · wf-500 firmwareMay 29, 2026
- CVE-2025-4127537Monitor
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the
CriticalCVSS 9.3No exploitEPSS 1%waterfall-security · wf-500 firmwareMay 29, 2026
- CVE-2025-4127637Monitor
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the
CriticalCVSS 9.3No exploitEPSS 1%waterfall-security · wf-500 firmwareMay 29, 2026
- CVE-2025-4127737Monitor
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the
CriticalCVSS 9.3No exploitEPSS 1%waterfall-security · wf-500 firmwareMay 29, 2026
- CVE-2025-4127237Monitor
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the
CriticalCVSS 9.3No exploitEPSS 1%waterfall-security · wf-500 firmwareMay 29, 2026
- CVE-2025-4126937Monitor
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the
CriticalCVSS 9.3No exploitEPSS 1%waterfall-security · wf-500 firmwareMay 29, 2026
- CVE-2025-4127037Monitor
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the
CriticalCVSS 9.3No exploitEPSS 1%waterfall-security · wf-500 firmwareMay 29, 2026
- CVE-2025-4127337Monitor
Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500
CriticalCVSS 9.3No exploitEPSS 0%waterfall-security · wf-500 firmwareMay 29, 2026
- CVE-2025-4126835Monitor
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version
HighCVSS 8.8No exploitEPSS 0%waterfall-security · wf-500 firmwareMay 29, 2026
- CVE-2025-4126534Monitor
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the
HighCVSS 8.6No exploitEPSS 1%waterfall-security · wf-500 firmwareMay 29, 2026
- CVE-2025-4126634Monitor
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the
HighCVSS 8.6No exploitEPSS 1%waterfall-security · wf-500 firmwareMay 29, 2026
- CVE-2025-4126734Monitor
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the
HighCVSS 8.5No exploitEPSS 1%waterfall-security · wf-500 firmwareMay 29, 2026
- CVE-2025-4127934Monitor
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the
HighCVSS 8.6No exploitEPSS 1%waterfall-security · wf-500 firmwareMay 29, 2026
- CVE-2025-4127134Monitor
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.
HighCVSS 8.7No exploitEPSS 0%waterfall-security · wf-500 firmwareMay 29, 2026
- CVE-2025-4128130Monitor
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Wate
HighCVSS 7.5No exploitEPSS 1%waterfall-security · wf-500 firmwareMay 29, 2026
- CVE-2025-4128030Monitor
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that
HighCVSS 7.5No exploitEPSS 0%waterfall-security · wf-500 firmwareMay 29, 2026
- CVE-2025-4127830Monitor
Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that allows attack
HighCVSS 7.5No exploitEPSS 0%waterfall-security · wf-500 firmwareMay 29, 2026