A10networks develops load-balancing and application-delivery infrastructure products such as the Thunder Application Delivery Controller and ACOS Web Application Firewall, widely deployed in the network edge to manage traffic and enforce security policy. Vulnerabilities affecting this vendor skew toward critical severity and frequently acquire public exploit code, with recurring exposure centering on input-handling and command-injection weakness classes including path traversal, OS command injection, SQL injection, and exposure of sensitive information—typical of internet-facing appliances that parse untrusted traffic at scale. Defenders should prioritize patching this vendor's disclosures and restrict management access to these devices; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by A10networks over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-5390HIGH Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of | Aug 6, 2018 | 7.5 | 66 | NO | NO |
CVE-2020-24384CRITICAL A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution (RCE) vulnerability that could be used to compromise affecte | Nov 10, 2020 | 9.8 | 32 | NO | NO |
CVE-2018-15904CRITICAL A10 ACOS Web Application Firewall (WAF) 2.7.1 and 2.7.2 before 2.7.2-P12, 4.1.0 before 4.1.0-P11, 4.1.1 before 4.1.1-P8, and 4.1.2 before 4.1.2-P4 mishandles the configured rules f | Aug 27, 2018 | 9.8 | 29 | NO | NO |
CVE-2014-3976MEDIUM Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allows remote attackers to cause a denial of service (crash) and | Jun 5, 2014 | 5.0 | 27 | NO | YES |
CVE-2024-30368HIGH A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Jun 6, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-30369HIGH A10 Thunder ADC Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations | Jun 6, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-42130HIGH A10 Thunder ADC FileMgmtExport Directory Traversal Arbitrary File Read and Deletion Vulnerability. This vulnerability allows remote attackers to read and delete arbitrary files on | May 3, 2024 | 8.8 | 22 | NO | NO |
CVE-2016-10213MEDIUM A10 AX1030 and possibly other devices with software before 2.7.2-P8 uses random GCM nonce generations, which makes it easier for remote attackers to obtain the authentication key a | Feb 8, 2017 | 5.9 | 20 | NO | NO |
CVE-2023-42129MEDIUM A10 Thunder ADC ShowTechDownloadView Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affec | May 3, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by A10networks.
Media articles that mention a CVE ID that affects a product developed by A10networks — matched by CVE ID, not by vendor name.