CVE-2025-46405
7.5F5 · BIG-IP
A stack-based buffer overflow in the F5 BIG-IP APM Traffic Management Microkernel (TMM) allows unauthenticated remote attackers to cause a denial of service via specifically crafted traffic.
Executive summary
A critical stack-based buffer overflow vulnerability in F5 BIG-IP APM could allow remote, unauthenticated attackers to cause a service crash through traffic manipulation.
Vulnerability
The vulnerability is a stack-based buffer overflow (CWE-121) occurring within the Traffic Management Microkernel (TMM) when Network Access is configured on a BIG-IP APM virtual server. The CVSS vector indicates that the attack requires no authentication and can be performed remotely by sending undisclosed, malformed traffic.
Business impact
Successful exploitation of this vulnerability results in the termination of the TMM process, leading to a complete denial of service for the affected BIG-IP device. Given the critical role of BIG-IP in traffic management and load balancing, such an outage could cause significant operational disruption, loss of service availability, and potential business interruption. With a CVSS score of 7.5, this high-severity flaw demands immediate attention to ensure infrastructure stability.
Remediation
Immediate Action: Update affected F5 BIG-IP systems to the patched versions as recommended in the official vendor advisory (K000151546), ensuring systems are moved to version 17.5.0 or later where applicable.
Proactive Monitoring: Monitor system logs for unexpected TMM process terminations or repeated crashes of the APM module, which may indicate exploitation attempts.
Compensating Controls: While a permanent patch is required, administrators should verify that perimeter firewalls are configured to drop malformed or anomalous traffic patterns directed toward the APM virtual servers.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit available.
Analyst recommendation
Organizations utilizing F5 BIG-IP APM must prioritize the identification of affected versions within their environment. Given the potential for remote denial of service, applying the vendor-supplied updates is the only definitive way to mitigate this risk. Security teams should schedule maintenance windows immediately to implement these patches and restore the integrity of their traffic management infrastructure.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.