Impact
The likely attack vector is the Console WebUI in Waterfall WF-500 TX and RX Hosts. A critical OS Command Injection flaw has been discovered in that interface. The vulnerability allows arbitrary operating system commands to run without authentication, leading to complete compromise of the device's operating environment. Based on the description, it is inferred that this issue stems from improper neutralization of special elements in OS command construction.
Affected Systems
Affected are Waterfall WF-500 devices running firmware version 7.9.1.0 R2502171040. Both TX and RX hosts expose the vulnerable Console WebUI interface. Based on the description, it is inferred that the vulnerability applies to all installations of this firmware revision.
Risk and Exploitability
The CVSS score of 9.3 identifies this flaw as critical. The EPSS score is 1%, indicating a moderate probability of exploitation, but the lack of authentication requirements and the ability to execute system commands create a high likelihood of exploitation. The vulnerability is not currently listed in CISA KEV, but the potential for remote code execution remains a significant threat. The likely attack vector is the web UI over the network, and based on the description it is inferred that attackers can trigger the flaw without prior authentication, gaining full control of the host.
OpenCVE Enrichment