CVE-2025-53868
8.7F5 · BIG-IP
A highly privileged authenticated attacker can bypass Appliance mode restrictions in F5 BIG-IP via SCP or SFTP, potentially leading to OS command injection.
Executive summary
F5 BIG-IP contains a vulnerability that allows authenticated attackers with high privileges to bypass restricted Appliance mode settings and execute arbitrary OS commands.
Vulnerability
This is an OS command injection vulnerability (CWE-78) triggered when an attacker with high-level administrative access leverages SCP or SFTP to escape the intended constraints of Appliance mode.
Business impact
The ability to bypass Appliance mode restrictions grants an attacker unauthorized control over the underlying operating system of critical networking infrastructure. Given the CVSS score of 8.7, this vulnerability poses a high risk of complete system compromise, potentially allowing an attacker to intercept traffic, modify configurations, or disrupt network services essential to business operations.
Remediation
Immediate Action: Upgrade F5 BIG-IP instances to the fixed versions specified in the vendor security advisory K000151902.
Proactive Monitoring: Review SCP and SFTP access logs for unusual command patterns or unauthorized attempts to access restricted file paths.
Compensating Controls: Restrict access to SCP and SFTP services to only known, trusted administrative IP addresses to minimize the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations utilizing F5 BIG-IP must prioritize applying the provided security updates to address this command injection flaw. Because the vulnerability allows a bypass of critical security boundaries, patching should be scheduled during the next maintenance window to ensure the integrity of the appliance management environment.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.