CVE-2025-53521: F5 BIG-IP Unspecified Vulnerability
F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.
Other sources
When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).
— F5
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.5.1.317.1.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.1.6.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.1.10.8 - Upgrade
Upgrade
F5 BIG-IP APMto a version that resolves this vulnerability.Fixed in 15.1.10.8 - Upgrade
Upgrade
F5 BIG-IP APMto a version that resolves this vulnerability.Fixed in 16.1.6.1 - Upgrade
Upgrade
F5 BIG-IP APMto a version that resolves this vulnerability.Fixed in 17.5.1.317.1.3 - Compensating control
Follow applicable BOD 22-01 guidance for cloud services and discontinue use of F5 BIG-IP APM if vendor mitigations are unavailable; apply any vendor-provided mitigations for F5 BIG-IP APM until the listed fixed versions can be deployed.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53521?
CVE-2025-53521 is considered a high severity vulnerability due to its potential to terminate the Traffic Management Microkernel.
How do I fix CVE-2025-53521?
To fix CVE-2025-53521, you should update F5 BIG-IP APM to the latest patched version according to the vendor's advisory.
Which versions of BIG-IP APM are affected by CVE-2025-53521?
CVE-2025-53521 affects F5 BIG-IP APM versions 15.1.0 to 15.1.10, 16.1.0 to 16.1.6, and 17.1.0 to 17.5.1.
Does CVE-2025-53521 impact performance?
Yes, CVE-2025-53521 can impact performance by causing the Traffic Management Microkernel to unexpectedly terminate.
What are the potential consequences of CVE-2025-53521?
The potential consequences of CVE-2025-53521 include service disruptions and security risks due to the termination of network traffic management.