CVE-2025-58120
7.5F5 · BIG-IP Next
A NULL pointer dereference in F5 BIG-IP Next products allows unauthenticated remote attackers to trigger a Traffic Management Microkernel (TMM) termination via specifically crafted HTTP/2 traffic.
Executive summary
A critical denial of service vulnerability in F5 BIG-IP Next products allows remote, unauthenticated attackers to crash the Traffic Management Microkernel via malformed HTTP/2 traffic.
Vulnerability
This is a NULL pointer dereference vulnerability (CWE-476) occurring when the system processes HTTP/2 Ingress traffic. The vulnerability is exploitable by unauthenticated remote attackers who can send crafted traffic to force a crash of the Traffic Management Microkernel (TMM).
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk due to the potential for complete service disruption. Successful exploitation results in the termination of the TMM, which effectively halts all traffic processing for the affected BIG-IP instance. This leads to immediate denial of service for any applications or services relying on the impacted ingress controller, potentially causing significant operational downtime and impacting business continuity.
Remediation
Immediate Action: Upgrade to the patched versions specified in F5 security advisory K000156623 to resolve the underlying NULL pointer dereference.
Proactive Monitoring: Monitor system logs for frequent TMM restarts or crash reports and inspect ingress traffic patterns for anomalous HTTP/2 requests.
Compensating Controls: Deploy a Web Application Firewall or ingress security policy to filter or rate-limit HTTP/2 traffic if immediate patching is not feasible.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high impact of a service-wide denial of service, administrators must prioritize the identification of affected BIG-IP Next deployments. Apply the vendor-provided patches as soon as possible to ensure the stability of the Traffic Management Microkernel and prevent unauthorized service termination.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.