F5-K000152678: Low severity F5 BIG-IP Next SPK vulnerability
Published Jul 23, 2025
·Updated
In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
Affected Software
5 affected components
F5 BIG-IP Next SPK>=2.0.0<=2.0.1
F5 BIG-IP Next SPK>=1.7.0<=1.9.2
F5 BIG-IP Next CNF>=2.0.0<=2.0.1
F5 BIG-IP Next CNF>=1.1.0<=1.4.1
F5 BIG-IP Next for Kubernetes=2.0.0
Event History
Jul 23, 2025
Advisory Published
via F5·03:41 PM
Data Sourced
via F5·03:41 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of F5-K000152678?
The severity of F5-K000152678 is considered to be high due to the potential for sensitive filenames to be hidden in TAR archives.
2
How do I fix F5-K000152678?
To fix F5-K000152678, upgrade your affected software version to the latest recommended version provided by F5.
3
Which F5 products are affected by F5-K000152678?
F5-K000152678 affects F5 BIG-IP Next SPK, BIG-IP Next CNF, and BIG-IP Next for Kubernetes across specified versions.
4
What is the impact of F5-K000152678 on my system?
The impact of F5-K000152678 is that it allows attackers to manipulate TAR archives to obscure filenames from listings, posing a security risk.
5
Is there any workaround for F5-K000152678?
Currently, there are no documented workarounds for F5-K000152678 other than upgrading to a non-affected version.