Vulnerability Advisories

This page offers a comprehensive view of vulnerabilities identified by Nozomi Networks in critical OT, ICS, and IoT environments, showcasing the deep expertise and dedication of our world-class Security Research team.

Each advisory represents our ongoing effort to enhance the protection of industrial systems, identifying emerging threats before they can be exploited. Immediate protection is available through our Threat Intelligence (TI) subscription, supporting a proactive, forward-thinking defense strategy. For more on our responsible approach, refer to the Responsible Disclosure Policy.

Vulnerability Advisories

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Date Published
CVE ID
Vendor
Product
Type
Risk
Details
No items found.
CVE ID
CVE-2025-41670
Vendor
Phoenix Contact
Product
PLCnext family
Date Published
May 27, 2026
Type
Uncontrolled Search Path Element
Risk Score
High
CVE ID
CVE-2025-41669
Vendor
Phoenix Contact
Product
PLCnext family
Date Published
May 27, 2026
Type
Improper Verification of Cryptographic Signature
Risk Score
High
CVE ID
CVE-2025-41281
Vendor
Waterfall
Product
WF-500
Date Published
May 29, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
High
CVE ID
CVE-2025-41280
Vendor
Waterfall
Product
WF-500
Date Published
May 29, 2026
Type
Relative Path Traversal
Risk Score
High
CVE ID
CVE-2025-41279
Vendor
Waterfall
Product
WF-500
Date Published
May 29, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
High
CVE ID
CVE-2025-41278
Vendor
Waterfall
Product
WF-500
Date Published
May 29, 2026
Type
Out-of-bounds Read
Risk Score
High
CVE ID
CVE-2025-41277
Vendor
Waterfall
Product
WF-500
Date Published
May 29, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
Critical
CVE ID
CVE-2025-41276
Vendor
Waterfall
Product
WF-500
Date Published
May 29, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
Critical
CVE ID
CVE-2025-41275
Vendor
Waterfall
Product
WF-500
Date Published
May 29, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
Critical
CVE ID
CVE-2025-41274
Vendor
Waterfall
Product
WF-500
Date Published
May 29, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
Critical
CVE ID
CVE-2025-41273
Vendor
Waterfall
Product
WF-500
Date Published
May 29, 2026
Type
Authentication Bypass Using an Alternate Path or Channel
Risk Score
Critical
CVE ID
CVE-2025-41272
Vendor
Waterfall
Product
WF-500
Date Published
May 29, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
Critical
CVE ID
CVE-2025-41271
Vendor
Waterfall
Product
WF-500
Date Published
May 29, 2026
Type
Relative Path Traversal
Risk Score
High
CVE ID
CVE-2025-41270
Vendor
Waterfall
Product
WF-500
Date Published
May 29, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
Critical
CVE ID
CVE-2025-41269
Vendor
Waterfall
Product
WF-500
Date Published
May 29, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
Critical

Take the next step.

Discover how easy it is to identify and respond to cyber threats by automating your OT and IoT asset discovery, inventory, and management.