Radware develops a focused portfolio of application-delivery and web-application firewall products, including its Alteon load balancers, AppWall, and cloud-based WAF offerings that protect web infrastructure. The vendor's vulnerability surface centers on input-handling and encoding weaknesses affecting these edge-facing products, with recurring patterns in improper input validation, output encoding flaws, HTTP request smuggling, and sensitive-information disclosure that reflect the parsing demands of request-inspection and traffic-management roles. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Radware over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17427MEDIUM Radware Alteon devices with a firmware version between 31.0.0.0-31.0.3.0 are vulnerable to an adaptive-chosen ciphertext attack ("Bleichenbacher attack"). This allows an attacker t | Dec 13, 2017 | 5.9 | 38 | NO | YES |
CVE-2024-56524CRITICAL Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by adding a special character to the request. | May 12, 2025 | 9.1 | 26 | NO | NO |
CVE-2024-56523CRITICAL Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by placing random data in the HTTP request body when using the HTT | May 12, 2025 | 9.1 | 26 | NO | NO |
CVE-2009-2301HIGH The radware AppWall Web Application Firewall (WAF) 1.0.2.6, with Gateway 4.6.0.2, allows remote attackers to read source code via a direct request to (1) funcs.inc, (2) defines.inc | Jul 2, 2009 | 7.8 | 20 | NO | NO |
CVE-2016-10212MEDIUM Radware devices use the same value for the first two GCM nonces, which allows remote attackers to obtain the authentication key and spoof data via a "forbidden attack," a similar i | Feb 8, 2017 | 5.9 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Radware.
Media articles that mention a CVE ID that affects a product developed by Radware — matched by CVE ID, not by vendor name.