CVE-2025-59481
8.7F5 · BIG-IP
An authenticated vulnerability in F5 BIG-IP iControl REST and tmsh allows attackers with Resource Administrator privileges to execute arbitrary system commands with elevated permissions.
Executive summary
An authenticated command execution vulnerability in F5 BIG-IP allows attackers with administrator privileges to escalate their access and execute system commands, posing a severe risk to infrastructure integrity.
Vulnerability
The vulnerability involves improper privilege management within the iControl REST and TMOS Shell (tmsh) interfaces, categorized as CWE-250 (Execution with Unnecessary Privileges), allowing an authenticated attacker with at least a resource administrator role to bypass security boundaries.
Business impact
Successful exploitation of this flaw allows an attacker to execute arbitrary system commands, which can lead to full system compromise, unauthorized data access, or the disruption of critical network services. With a CVSS score of 8.7, this vulnerability is classified as High severity, reflecting the significant potential for lateral movement and systemic impact within enterprise environments.
Remediation
Immediate Action: Update F5 BIG-IP systems to the patched versions listed in the vendor advisory (K000156642) immediately.
Proactive Monitoring: Audit iControl REST and tmsh access logs for unusual command execution patterns or unauthorized administrative activity.
Compensating Controls: Restrict administrative access to management interfaces to trusted IP addresses and enforce the principle of least privilege for all administrative accounts.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for complete system control, administrators should prioritize patching their BIG-IP environments as soon as possible. Organizations must verify that their current software versions are updated to the non-vulnerable releases specified by F5 to prevent potential escalation and unauthorized system commands.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.