CVE-2025-53860: F5OS-A FIPS HSM vulnerability
Published Oct 15, 2025
·Updated
A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIPS hardware security module (HSM) information on F5 rSeries systems.
Affected Software
5 affected componentsFixes available
F5 F5OS-A=1.8.0, >=1.5.1<=1.5.2
1.8.31.5.3
All of the following
Any of the following
F5 F5OS-A>=1.5.1<1.5.3
F5 F5OS-A=1.8.0
Any of the following
F5 R10920-df
F5 R5920-df
Event History
Oct 15, 2025
Advisory Published
via F5·11:16 AM
Data Sourced
via F5·11:16 AM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·03:15 PM
Data Sourced
via MITRE·03:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-53860?
CVE-2025-53860 is a high severity vulnerability that allows unauthorized access to sensitive HSM information.
2
How do I fix CVE-2025-53860?
To fix CVE-2025-53860, upgrade to F5OS-A version 1.8.31.5.3 or later.
3
What systems are affected by CVE-2025-53860?
CVE-2025-53860 affects F5 rSeries systems running F5OS-A versions 1.5.1 to 1.8.0.
4
Who can exploit the CVE-2025-53860 vulnerability?
CVE-2025-53860 can be exploited by a highly privileged authenticated attacker with access to the system.
5
What type of information can be accessed through CVE-2025-53860?
CVE-2025-53860 allows attackers to access sensitive FIPS hardware security module (HSM) information.