Impact
An OS Command Injection flaw in the Console WebUI of Waterfall WF-500 devices uses improper neutralization of special elements to allow attackers to run arbitrary operating system commands. This weakness, classified as CWE-78, gives a remote, unauthenticated attacker full control over the host OS, enabling execution of malicious scripts, privilege escalation, or network infiltration. The vulnerability is severe, with a CVSS score of 9.3 indicating maximum impact on confidentiality, integrity, and availability.
Affected Systems
Waterfall WF-500 TX and RX Hosts running firmware version 7.9.1.0 R2502171040 are affected. Only devices with this exact build are vulnerable; newer releases may contain the fix.
Risk and Exploitability
The high CVSS score reflects the critical nature of this flaw. With an EPSS score of 1%, exploitation is considered possible but relatively rare; however, the absence of authentication and the direct exposure of the Console WebUI still make it highly likely if the interface is reachable from the internet or an untrusted network. The flaw is not listed in the CISA KEV catalog, but the potential for widespread compromise warrants immediate attention. Attackers can perform the exploit remotely by accessing the WebUI, sending specially crafted input, and triggering system commands without any prior authentication.
OpenCVE Enrichment