CVE-2025-55670: BIG-IP Next (CNF, SPK, and Kubernetes) vulnerability
On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55670?
CVE-2025-55670 is classified as a critical vulnerability due to its potential to cause system instability.
How do I fix CVE-2025-55670?
To mitigate CVE-2025-55670, upgrade to the patched versions of F5 BIG-IP Next SPK and F5 BIG-IP Next CNF as specified by F5.
Which F5 products are affected by CVE-2025-55670?
CVE-2025-55670 affects F5 BIG-IP Next SPK, F5 BIG-IP Next CNF, and specific versions of F5 BIG-IP Next for Kubernetes.
What causes the issue in CVE-2025-55670?
CVE-2025-55670 is triggered by repeated undisclosed API calls that lead to the termination of the Traffic Management Microkernel (TMM).
Is there a workaround for CVE-2025-55670?
Currently, no official workaround is provided for CVE-2025-55670; it is recommended to apply the version updates immediately.