Description
Reflected Cross-Site Scripting (XSS) Vulnerability in Radware Alteon 34.5.4.0 vADC load-balancer allows an attacker to inject malicious scripts into the website, potentially leading to unauthorized actions, data theft, or other malicious activities.
Published: 2026-04-14
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting that can lead to unauthorized actions or data theft
Action: Apply Patch
AI Analysis

Impact

Radware Alteon 34.5.4.0 vADC load‑balancer contains a reflected Cross‑Site Scripting flaw that allows an attacker to inject malicious scripts into responses returned to a user. The injected scripts can execute in the victim’s browser, potentially enabling cookie theft, session hijacking, or execution of further malicious code. The vulnerability is a reflected XSS and could be exploited through crafted URLs or form submissions that pass through the load balancer.

Affected Systems

The flaw affects Radware’s Alteon vADC load‑balancer running version 34.5.4.0. Any deployment of this specific version is at risk until a newer, patched release is applied.

Risk and Exploitability

No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog; however, reflected XSS is widely exploitable through normal web traffic. Attackers can trigger the vulnerability by sending a crafted request to the load balancer, making the risk moderate to high, especially if users are permitted to input arbitrary data that the balancer reflects. The absence of an official fix in the provided data means the compromise remains possible until remediation is applied.

Generated by OpenCVE AI on April 14, 2026 at 20:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Radware Alteon to a version newer than 34.5.4.0 that contains the fix
  • If an upgrade is not immediately possible, restrict or sanitize incoming query parameters on the load‑balancer to prevent script injection
  • Enable or enforce a strict Content‑Security‑Policy on downstream applications so that even reflected scripts are blocked from execution
  • Monitor web traffic for anomalous requests that may indicate exploitation attempts
  • Consult Radware’s product support for any interim mitigations or additional configuration guidance

Generated by OpenCVE AI on April 14, 2026 at 20:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 15 Apr 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Radware
Radware alteon
Weaknesses CWE-79
Vendors & Products Radware
Radware alteon

Tue, 14 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Description Reflected Cross-Site Scripting (XSS) Vulnerability in Radware Alteon 34.5.4.0 vADC load-balancer allows an attacker to inject malicious scripts into the website, potentially leading to unauthorized actions, data theft, or other malicious activities.
Title Radware Alteon has a reflected XSS vulnerability
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-04-14T17:52:21.871Z

Reserved: 2026-04-07T16:18:19.839Z

Link: CVE-2026-5754

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-14T18:17:39.487

Modified: 2026-04-14T18:17:39.487

Link: CVE-2026-5754

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T14:41:09Z

Weaknesses