Nozomi Networks Waterfall WF-500 TX OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the Administration WebUI of the Nozomi Networks Waterfall WF-500 TX Host, specifically in version 7.9.1.0 R2502171040. This vulnerability, categorized as CWE-78, allows remote authenticated attackers to execute arbitrary operating system commands on the affected host.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of operating system commands on the affected WF-500 TX Host.

Added: May 29, 2026, 12:25 PM
Updated: May 29, 2026, 12:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.2
remediation
0.0
relevance
9.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.