CVE-2025-53521

9.5 CISA KEV

F5 · BIG-IP

A stack-based buffer overflow in F5 BIG-IP APM allows unauthenticated remote attackers to achieve remote code execution via malicious traffic.

Executive summary

This critical remote code execution vulnerability in F5 BIG-IP is being actively exploited in the wild and requires immediate remediation to prevent full system compromise.

Vulnerability

The flaw is a stack-based buffer overflow (CWE-121) triggered when a BIG-IP APM access policy is configured on a virtual server. An unauthenticated remote attacker can send specifically crafted traffic to achieve remote code execution with root-level privileges on the underlying operating system.

Business impact

The vulnerability carries a CVSS score of 9.5, reflecting its critical severity and the potential for total system compromise. Successful exploitation grants attackers root-level access, facilitating the installation of persistent backdoors, data exfiltration, and lateral movement within the network. This risk is compounded by evidence linking the exploitation to sophisticated threat actors, potentially resulting in significant reputational damage and operational disruption.

Remediation

Immediate Action: Upgrade all affected BIG-IP instances to the patched versions: 17.5.1.3, 17.1.3, 16.1.6.1, or 15.1.10.8.

Proactive Monitoring: Review system logs for anomalous traffic patterns directed at APM endpoints and monitor for the presence of unauthorized web shells or unexpected root-level processes.

Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to inspect and filter malicious traffic patterns targeting APM access policies, though these should only serve as a temporary measure until patching is complete.

Exploitation status

Public Exploit Available: Yes (per CISA KEV listing and evidence of active exploitation).

Analyst recommendation

Given the confirmed active exploitation and the critical nature of the remote code execution risk, organizations must prioritize patching their F5 BIG-IP infrastructure immediately. Failure to apply the provided fixes exposes the enterprise to high-impact espionage and persistent adversary access. All affected devices should be treated as high-risk assets until the updates are verified as successfully installed.

More F5 CVEs

Sources

Originally found and disclosed by F5 would like to thank Kristian Vlaardingerbroek, Hugo Trippaers, and other people of Schuberg Philis, Bart Vrancken, Fo, per the CVE Program record.