CVE-2025-53856: TMM vulnerability
When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocity Acceleration (ePVA) feature, and the Auto Last Hop setting is disabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. The Auto Last Hop setting is enabled globally by default. For more information about the Auto Last Hop setting, refer to K13876: Overview of the Auto Last Hop setting (15.x - 17.x). To determine which BIG-IP platforms have an ePVA chip, refer to K12837: Overview of the ePVA feature.
Other sources
When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocity Acceleration (ePVA) feature, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. To determine which BIG-IP platforms have an ePVA chip refer to K12837: Overview of the ePVA feature https://my.f5.com/manage/s/article/K12837 . Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53856?
CVE-2025-53856 is rated as a high-severity vulnerability that can lead to potential traffic disruption.
How do I fix CVE-2025-53856?
To fix CVE-2025-53856, upgrade to the recommended versions of F5 BIG-IP: 17.5.1.317.1.3, 16.1.6.1, or 15.1.10.8.
What products are affected by CVE-2025-53856?
CVE-2025-53856 affects specific versions of F5 BIG-IP, particularly from the 17.5.0 to 17.5.1 range, 16.1.0 to 16.1.6, and 15.1.0 to 15.1.10.
What causes the vulnerability in CVE-2025-53856?
The vulnerability occurs when the embedded Packet Velocity Acceleration feature is enabled with the Auto Last Hop setting disabled.
Are there any mitigations for CVE-2025-53856?
Disabling the ePVA feature or the Auto Last Hop setting can mitigate risks associated with CVE-2025-53856 until a patch is applied.