PT-2026-44806 · Waterfall · Wf-500

Published

2026-05-29

·

Updated

2026-05-29

·

CVE-2025-41268

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete arbitrary files on the Host machines.

Fix

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2025-41268

Affected Products

Wf-500