CVE-2025-53474

7.5

F5 · BIG-IP

An iRule configuration issue in F5 BIG-IP allows unauthenticated remote attackers to cause a Traffic Management Microkernel (TMM) termination via specifically crafted traffic.

Executive summary

A critical denial of service vulnerability in F5 BIG-IP allows unauthenticated attackers to crash the Traffic Management Microkernel, resulting in service interruption.

Vulnerability

The vulnerability is a buffer overflow (CWE-120) triggered when an iRule utilizes the ILX::call command. This allows an unauthenticated attacker to send crafted traffic to a virtual server, forcing the TMM process to terminate unexpectedly.

Business impact

The successful exploitation of this vulnerability results in a total denial of service for the affected BIG-IP device, as the TMM process is responsible for core traffic management functions. Given the CVSS score of 7.5, this high severity flaw poses a significant risk to business continuity, potentially taking critical applications and services offline until the process is manually or automatically restored.

Remediation

Immediate Action: Upgrade to the fixed versions specified in the F5 security advisory K44517780 immediately to prevent system instability.

Proactive Monitoring: Monitor system logs for TMM process restarts or error messages related to ILX::call failures that may indicate an attempt to trigger this vulnerability.

Compensating Controls: If immediate patching is not possible, evaluate the necessity of ILX::call usage within iRules on exposed virtual servers and consider disabling the affected iRules as a temporary mitigation.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Organizations utilizing F5 BIG-IP should prioritize this update within their maintenance cycle. Because this vulnerability allows unauthenticated attackers to cause a service outage, the risk of instability is significant, and applying the vendor-provided patches is the only reliable method to resolve the underlying buffer overflow condition.

More F5 CVEs

Sources

Originally found and disclosed by F5, per the CVE Program record.