Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

A10networks

First CVE: Jun 5, 2014Active for: 12 yearsTotal CVEs: 9

A10networks develops load-balancing and application-delivery infrastructure products such as the Thunder Application Delivery Controller and ACOS Web Application Firewall, widely deployed in the network edge to manage traffic and enforce security policy. Vulnerabilities affecting this vendor skew toward critical severity and frequently acquire public exploit code, with recurring exposure centering on input-handling and command-injection weakness classes including path traversal, OS command injection, SQL injection, and exposure of sensitive information—typical of internet-facing appliances that parse untrusted traffic at scale. Defenders should prioritize patching this vendor's disclosures and restrict management access to these devices; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by A10networks over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 5, 2014
12 years ago
Most Recent CVE
Jun 6, 2024
778 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-5390HIGH
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of
Aug 6, 20187.566NONO
CVE-2020-24384CRITICAL
A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution (RCE) vulnerability that could be used to compromise affecte
Nov 10, 20209.832NONO
CVE-2018-15904CRITICAL
A10 ACOS Web Application Firewall (WAF) 2.7.1 and 2.7.2 before 2.7.2-P12, 4.1.0 before 4.1.0-P11, 4.1.1 before 4.1.1-P8, and 4.1.2 before 4.1.2-P4 mishandles the configured rules f
Aug 27, 20189.829NONO
CVE-2014-3976MEDIUM
Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allows remote attackers to cause a denial of service (crash) and
Jun 5, 20145.027NOYES
CVE-2024-30368HIGH
A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations
Jun 6, 20248.825NONO
CVE-2024-30369HIGH
A10 Thunder ADC Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations
Jun 6, 20247.822NONO
CVE-2023-42130HIGH
A10 Thunder ADC FileMgmtExport Directory Traversal Arbitrary File Read and Deletion Vulnerability. This vulnerability allows remote attackers to read and delete arbitrary files on
May 3, 20248.822NONO
CVE-2016-10213MEDIUM
A10 AX1030 and possibly other devices with software before 2.7.2-P8 uses random GCM nonce generations, which makes it easier for remote attackers to obtain the authentication key a
Feb 8, 20175.920NONO
CVE-2023-42129MEDIUM
A10 Thunder ADC ShowTechDownloadView Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affec
May 3, 20246.519NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
33%
44%
22%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (11.1%)
Network7 (77.8%)
Unknown1 (11.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (77.8%)
High1 (11.1%)
Unknown1 (11.1%)
User Interaction
None8 (88.9%)
Unknown1 (11.1%)
Required0 (0.0%)
Privileges Required
Low4 (44.4%)
High0 (0.0%)
None4 (44.4%)
Unknown1 (11.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by A10networks.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by A10networks — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For A10networks's Products

View all 3 CNAs →

Top CWEs