Critical Flaw in Radware Cloud Web App Firewall Allows Filter Bypass

Critical Flaw in Radware Cloud Web App Firewall Allows Filter Bypass

Security experts have identified major weaknesses in Radware’s Cloud Web Application Firewall (WAF), which could allow cybercriminals to bypass its defenses, leaving critical web applications vulnerable to attack.

The flaws, marked as CVE-2024-56523 and CVE-2024-56524, were made public on May 7, 2025, by CERT/CC, sparking serious concern for businesses that rely on Radware’s security platform.

Vulnerability Breakdown

The first vulnerability (CVE-2024-56523) stems from how Radware’s Cloud WAF handles specially crafted HTTP GET requests containing random data in the body. When these requests are formed in a particular way, the firewall fails to filter them properly, potentially allowing malicious payloads to pass through and target the underlying web application.

The second flaw (CVE-2024-56524) arises from improper validation of special characters in user input. Attackers can exploit this by inserting specific characters into their requests, bypassing the WAF’s filtering mechanisms and enabling harmful content to reach the protected application.

This flaw raises serious concerns, as WAFs are meant to be a primary line of defense against various online threats. If these security gaps remain unchecked, attackers could circumvent this critical defense layer, potentially exposing sensitive data or compromising systems.

Severity and Impact

VulDB has rated the vulnerabilities as critical, with a CVSS score of 5.3, signaling a moderate but notable risk. These vulnerabilities are particularly concerning because they allow attackers with knowledge of the flaws to deliver harmful content directly to a protected web application that would otherwise be blocked by the firewall.

While Radware has reportedly patched these issues in newer updates, the lack of an official acknowledgment from the company at the time of the initial discovery, as reported by researcher Oriol Gegundez, has drawn additional scrutiny.

Recommendations for Mitigation

Given the potential for exploitation, cybersecurity professionals urge organizations using Radware Cloud WAF to ensure their systems are updated to the latest version of the software. It’s also recommended that additional layers of security be implemented as part of a multi-faceted defense strategy to mitigate potential risks from this and other vulnerabilities.

The vulnerabilities were first reported by Oriol Gegundez, with Kevin Stephens and Ben Koo providing the associated security advisory.

More Articles & Posts