CVE-2025-54858
7.5F5 · BIG-IP
A vulnerability in F5 BIG-IP Advanced WAF and ASM allows unauthenticated attackers to cause a denial of service by sending specifically crafted requests that terminate the bd process.
Executive summary
A critical denial of service vulnerability in F5 BIG-IP Advanced WAF and ASM allows unauthenticated remote attackers to crash the security policy enforcement process.
Vulnerability
This is an uncontrolled recursion flaw (CWE-674) triggered when processing a malformed JSON schema within a security policy. The vulnerability is exploitable by unauthenticated attackers via the network, as indicated by the CVSS attack vector.
Business impact
Successful exploitation results in the termination of the bd process, which is responsible for security policy enforcement on the BIG-IP device. This leads to a denial of service for the protected applications, potentially bypassing security controls or rendering services unavailable. With a CVSS score of 7.5, this represents a high-severity risk that directly impacts service availability and operational continuity.
Remediation
Immediate Action: Upgrade to the patched versions identified in the F5 security advisory K000156621 to resolve the underlying recursion flaw.
Proactive Monitoring: Monitor system logs for frequent restarts of the bd process or sudden spikes in resource consumption that may indicate exploitation attempts.
Compensating Controls: While a permanent patch is the only effective resolution, ensure that administrative access to the management interface is restricted to trusted networks to reduce the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for service disruption and the ease of exploitation over the network, organizations using F5 BIG-IP with Advanced WAF or ASM modules must prioritize the application of vendor-provided updates. Failure to patch these systems leaves critical infrastructure vulnerable to denial of service attacks that can cripple web application security enforcement.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.