CVE-2025-41280
Published: 29 May 2026
Summary
CVE-2025-41280 is a high-severity Relative Path Traversal (CWE-23) vulnerability in Waterfall-Security Wf-500 Firmware. Its CVSS base score is 7.5 (High).
Operationally, ranked at the 4.2th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-210000
Vulnerability details
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector…
more
is configured and file compression is enabled.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.