CVE-2025-36525: BIG-IP APM PingAccess Virtual Server Vulnerability
When a BIG-IP APM PingAccess profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.
Other sources
When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36525?
The severity of CVE-2025-36525 has not been disclosed, but it involves a TMM termination issue under specific conditions.
How do I fix CVE-2025-36525?
To mitigate CVE-2025-36525, ensure your BIG-IP APM virtual server is not using a PingAccess profile or upgrade to a supported version.
What versions of BIG-IP APM are affected by CVE-2025-36525?
CVE-2025-36525 affects all versions of F5 Networks BIG-IP APM that are configured with a PingAccess profile.
Can CVE-2025-36525 be exploited remotely?
Yes, CVE-2025-36525 can potentially be exploited through undisclosed requests leading to TMM termination.
What are the consequences of CVE-2025-36525?
Exploiting CVE-2025-36525 may result in unintended termination of TMM, affecting the availability of the BIG-IP APM service.