CVE-2025-48008

7.5

F5 · BIG-IP

A Use After Free vulnerability in F5 BIG-IP systems allows unauthenticated remote attackers to cause a denial of service by triggering a Traffic Management Microkernel (TMM) termination.

Executive summary

A critical denial of service vulnerability in F5 BIG-IP products enables unauthenticated remote attackers to crash the Traffic Management Microkernel (TMM) via specifically crafted Multipath TCP traffic.

Vulnerability

This is a Use After Free (CWE-416) vulnerability occurring within the Traffic Management Microkernel (TMM) when a virtual server is configured with a TCP profile utilizing Multipath TCP (MPTCP). The flaw allows an unauthenticated remote attacker to trigger a system crash by sending specific traffic patterns.

Business impact

The vulnerability carries a CVSS score of 7.5, reflecting its high impact on system availability. Successful exploitation results in the termination of the TMM service, causing an immediate denial of service for all traffic processed by the affected device. This poses a significant risk to business continuity for organizations relying on BIG-IP for load balancing and application delivery.

Remediation

Immediate Action: Upgrade to the fixed versions provided by the vendor: BIG-IP 17.5.0 or later, BIG-IP Next SPK 2.0.0 or later, and BIG-IP Next CNF 2.0.0 or later.

Proactive Monitoring: Monitor system logs for TMM process restarts or unexpected service termination events which may indicate successful exploitation or instability.

Compensating Controls: If immediate patching is not feasible, disable Multipath TCP on affected virtual server profiles to eliminate the attack vector.

Exploitation status

Public Exploit Available: No (exploit_available unknown).

Analyst recommendation

Given the potential for complete service disruption, organizations should prioritize the identification of all F5 BIG-IP units currently running the affected versions. If an immediate software update is not possible, the configuration change to disable Multipath TCP should be implemented as a temporary measure to ensure service uptime and mitigate the risk of remote service termination.

More F5 CVEs

Sources

Originally found and disclosed by F5, per the CVE Program record.