Nozomi Networks Waterfall OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the Console WebUI of Nozomi Networks Waterfall WF-500 TX and RX Hosts, version 7.9.1.0 R2502171040. This vulnerability, categorized as CWE-78, allows remote unauthenticated attackers to execute arbitrary operating system commands on the affected device.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of operating system commands on the affected device.

Added: May 29, 2026, 12:21 PM
Updated: May 29, 2026, 12:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
9.7
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.