Nozomi Networks Waterfall OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the Console WebUI of Nozomi Networks Waterfall WF-500 TX and RX Hosts, specifically in version 7.9.1.0 R2502171040. This vulnerability, categorized as CWE-78, allows remote unauthenticated attackers to execute arbitrary operating system commands on the affected device.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of operating system commands on the affected device, potentially allowing for further exploitation or manipulation of the system.

Added: May 29, 2026, 12:24 PM
Updated: May 29, 2026, 12:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
9.7
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.