Database/Control plane, storage & DevOps

A10 Thunder ADC (FileMgmtExport): An authenticated attacker can walk outside the intended export directory
Impact
An authenticated attacker can walk outside the intended export directory via the FileMgmtExport component, reading or deleting arbitrary files on the ADC — enough to pull sensitive configuration data or sabotage the device by deleting files it depends on.
Who can reach it
Requires authentication to the management interface, then a crafted path sent to the file-export functionality.
What to do
Software upgrade to the fixed ACOS release per A10's security advisory. Standard upgrade-and-reboot per Thunder ADC instance; coordinate with failover if this device is in the active traffic path for a cluster.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.