CVE-2025-53474
7.5F5 · BIG-IP
An iRule configuration issue in F5 BIG-IP allows unauthenticated remote attackers to cause a Traffic Management Microkernel (TMM) termination via specifically crafted traffic.
Executive summary
A critical denial of service vulnerability in F5 BIG-IP allows unauthenticated attackers to crash the Traffic Management Microkernel, resulting in service interruption.
Vulnerability
The vulnerability is a buffer overflow (CWE-120) triggered when an iRule utilizes the ILX::call command. This allows an unauthenticated attacker to send crafted traffic to a virtual server, forcing the TMM process to terminate unexpectedly.
Business impact
The successful exploitation of this vulnerability results in a total denial of service for the affected BIG-IP device, as the TMM process is responsible for core traffic management functions. Given the CVSS score of 7.5, this high severity flaw poses a significant risk to business continuity, potentially taking critical applications and services offline until the process is manually or automatically restored.
Remediation
Immediate Action: Upgrade to the fixed versions specified in the F5 security advisory K44517780 immediately to prevent system instability.
Proactive Monitoring: Monitor system logs for TMM process restarts or error messages related to ILX::call failures that may indicate an attempt to trigger this vulnerability.
Compensating Controls: If immediate patching is not possible, evaluate the necessity of ILX::call usage within iRules on exposed virtual servers and consider disabling the affected iRules as a temporary mitigation.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Organizations utilizing F5 BIG-IP should prioritize this update within their maintenance cycle. Because this vulnerability allows unauthenticated attackers to cause a service outage, the risk of instability is significant, and applying the vendor-provided patches is the only reliable method to resolve the underlying buffer overflow condition.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.