CVE-2025-46265: F5OS vulnerability
Published May 7, 2025
·Updated
On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher privilege F5OS roles.
Affected Software
4 affected componentsFixes available
F5 F5OS-A=1.5.1
1.8.01.5.2
F5 F5OS-C>=1.6.0<=1.6.2
5
F5 F5OS-A=1.5.1
F5 F5OS-C>=1.6.0<=1.6.2
Event History
May 7, 2025
Advisory Published
via F5·12:48 PM
CVE Published
via MITRE·10:04 PM
Data Sourced
via MITRE·10:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-46265?
CVE-2025-46265 is classified as a critical severity vulnerability.
2
How do I fix CVE-2025-46265?
To mitigate CVE-2025-46265, upgrade to the patched versions of F5OS as specified by the vendor.
3
Who is affected by CVE-2025-46265?
Remotely authenticated users utilizing LDAP, RADIUS, or TACACS+ on F5OS versions 1.5.1 and 1.6.0 to 1.6.2 are affected by CVE-2025-46265.
4
What type of vulnerability is CVE-2025-46265?
CVE-2025-46265 is an improper authorization vulnerability.
5
Can CVE-2025-46265 allow escalation of privileges?
Yes, CVE-2025-46265 may allow remotely authenticated users to gain higher privilege roles on F5OS.