CVE-2025-58120: BIG-IP Next (CNF, SPK, and Kubernetes) vulnerability
Published Oct 15, 2025
·Updated
When HTTP/2 Ingress is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Affected Software
11 affected componentsFixes available
F5 BIG-IP Next SPK=2.0.0
2.0.1
F5 BIG-IP Next SPK>=1.7.0<=1.7.14
1.7.14
F5 BIG-IP Next CNF=2.0.0
2.0.1
F5 BIG-IP Next CNF>=1.1.0<=1.4.1
F5 BIG-IP Next for Kubernetes=2.0.0
2.1.0
F5 Big-ip Next Cloud-native Network Functions>=1.1.0<=1.4.1
F5 Big-ip Next Cloud-native Network Functions=2.0.0
F5 BIG-IP Next for Kubernetes=2.0.0
F5 Big-ip Next Service Proxy For Kubernetes>=1.7.0<1.7.14
F5 Big-ip Next Service Proxy For Kubernetes=1.7.14
F5 Big-ip Next Service Proxy For Kubernetes=2.0.0
Event History
Oct 15, 2025
Advisory Published
via F5·11:01 AM
Data Sourced
via F5·11:01 AM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-58120?
CVE-2025-58120 has a severity rating that indicates it could lead to traffic disruptions due to TMM termination.
2
How do I fix CVE-2025-58120?
To fix CVE-2025-58120, update your F5 BIG-IP Next SPK, Next CNF, or Next for Kubernetes to the applicable remedy versions.
3
Which versions are affected by CVE-2025-58120?
CVE-2025-58120 affects F5 BIG-IP Next SPK, Next CNF, and Next for Kubernetes in specific versions as detailed in its advisory.
4
What components are impacted by CVE-2025-58120?
CVE-2025-58120 impacts the Traffic Management Microkernel (TMM) when HTTP/2 Ingress is configured.
5
Is there a workaround for CVE-2025-58120?
There are no published workarounds for CVE-2025-58120; updating to the latest version is required for mitigation.