CVE-2025-54479
7.5F5 · BIG-IP
A vulnerability in F5 BIG-IP products allows unauthenticated, remote attackers to cause a Traffic Management Microkernel (TMM) termination via specifically crafted requests.
Executive summary
A critical vulnerability in F5 BIG-IP allows unauthenticated attackers to trigger a denial of service by causing the Traffic Management Microkernel to crash.
Vulnerability
This vulnerability is an out-of-bounds write (CWE-787) occurring when a classification profile is configured on a virtual server without an associated HTTP or HTTP/2 profile. Unauthenticated attackers can send undisclosed requests that lead to a termination of the Traffic Management Microkernel (TMM).
Business impact
Successful exploitation of this vulnerability results in a denial of service for the affected BIG-IP system, as the TMM process is critical for traffic processing. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to business continuity and service availability. Organizations relying on these devices for load balancing or traffic management may experience total service outages if an attacker triggers the crash.
Remediation
Immediate Action: Upgrade to the patched versions specified in the F5 security advisory K000151475 to resolve the underlying out-of-bounds write flaw.
Proactive Monitoring: Monitor system logs for TMM crashes or unexpected service restarts, and review traffic patterns for anomalous request types targeting virtual servers.
Compensating Controls: Ensure that virtual servers are configured with appropriate HTTP or HTTP/2 profiles where applicable, as the vulnerability specifically affects configurations lacking these profiles.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the potential for severe service disruption, administrators should prioritize patching the affected BIG-IP systems immediately. If an immediate upgrade is not feasible, review existing virtual server configurations to ensure they include HTTP or HTTP/2 profiles to mitigate the specific triggering condition for this vulnerability.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.