CVE-2024-56523: Radware Cloud Waf

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by placing random data in the HTTP request body when using the HTTP GET method.

Affected products

  • Radware Cloud Waf: before 2025-05-07 (fixed in 2025-05-07)

Published 2025-05-12. Last modified 2026-06-17.