CVE-2025-61938
7.5F5 · BIG-IP
An input validation flaw in F5 BIG-IP Advanced WAF and ASM allows unauthenticated attackers to cause a repeated crash of the bd process by providing URLs exceeding 1024 characters.
Executive summary
A critical denial of service vulnerability in F5 BIG-IP allows unauthenticated attackers to crash the security policy enforcement process, potentially bypassing security controls.
Vulnerability
The vulnerability involves improper validation of input length (CWE-1284) within the Data Guard Protection Enforcement setting. Unauthenticated attackers can trigger a repeated termination of the bd process by submitting URLs that exceed 1024 characters.
Business impact
This vulnerability poses a significant risk to network availability and security posture. Because the bd process is responsible for security policy enforcement, its repeated termination can lead to a denial of service or the potential bypass of configured security protections. With a CVSS score of 7.5, this high severity flaw necessitates prompt attention to prevent service disruption and maintain the integrity of the WAF infrastructure.
Remediation
Immediate Action: Upgrade to the fixed software versions as specified in the F5 security advisory (K000156624).
Proactive Monitoring: Monitor system logs for repeated crashes of the bd process and inspect incoming traffic for unusually long URL strings that may indicate exploitation attempts.
Compensating Controls: If patching is not immediately feasible, restrict access to the affected BIG-IP management interfaces and consider implementing upstream rate limiting to mitigate automated exploitation attempts.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The potential for a denial of service against a core security component makes this vulnerability a high priority for remediation. Administrators should verify their current BIG-IP version and apply the recommended updates immediately to ensure that the security enforcement engine remains stable and resilient against malicious input.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.