CVE-2025-58120

7.5

F5 · BIG-IP Next

A NULL pointer dereference in F5 BIG-IP Next products allows unauthenticated remote attackers to trigger a Traffic Management Microkernel (TMM) termination via specifically crafted HTTP/2 traffic.

Executive summary

A critical denial of service vulnerability in F5 BIG-IP Next products allows remote, unauthenticated attackers to crash the Traffic Management Microkernel via malformed HTTP/2 traffic.

Vulnerability

This is a NULL pointer dereference vulnerability (CWE-476) occurring when the system processes HTTP/2 Ingress traffic. The vulnerability is exploitable by unauthenticated remote attackers who can send crafted traffic to force a crash of the Traffic Management Microkernel (TMM).

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high severity risk due to the potential for complete service disruption. Successful exploitation results in the termination of the TMM, which effectively halts all traffic processing for the affected BIG-IP instance. This leads to immediate denial of service for any applications or services relying on the impacted ingress controller, potentially causing significant operational downtime and impacting business continuity.

Remediation

Immediate Action: Upgrade to the patched versions specified in F5 security advisory K000156623 to resolve the underlying NULL pointer dereference.

Proactive Monitoring: Monitor system logs for frequent TMM restarts or crash reports and inspect ingress traffic patterns for anomalous HTTP/2 requests.

Compensating Controls: Deploy a Web Application Firewall or ingress security policy to filter or rate-limit HTTP/2 traffic if immediate patching is not feasible.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high impact of a service-wide denial of service, administrators must prioritize the identification of affected BIG-IP Next deployments. Apply the vendor-provided patches as soon as possible to ensure the stability of the Traffic Management Microkernel and prevent unauthorized service termination.

More F5 CVEs

Sources

Originally found and disclosed by F5, per the CVE Program record.