CVE-2014-125125 - CVE House
Back to Database
Status published High CVE-2014-125125

A10 Networks AX Loadbalancer Path Traversal

Vulnerability Description

A path traversal vulnerability exists in A10 Networks AX Loadbalancer versions 2.6.1-GR1-P5, 2.7.0, and earlier. The vulnerability resides in the handling of the filename parameter in the /xml/downloads endpoint, which fails to properly sanitize user input. An unauthenticated attacker can exploit this flaw by sending crafted HTTP requests containing directory traversal sequences to read arbitrary files outside the intended directory. The files returned by the vulnerable endpoint are deleted from the system after retrieval. This can lead to unauthorized disclosure of sensitive information such as SSL certificates and private keys, as well as unintended file deletion.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-125125

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • xistence

Affected Vendor

A10 Networks

View all reports →

Affected Software

AX Series Loadbalancer
Vulnerable Versions:
0

Timeline

Official Publish: July 31st, 2025
Last Modified: May 15th, 2026
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)