CVE-2025-61955
8.8F5 · F5OS-A and F5OS-C
An authenticated local privilege escalation vulnerability exists in F5OS-A and F5OS-C systems due to improper neutralization of directives in dynamically evaluated code.
Executive summary
An authenticated local attacker can escalate privileges on F5OS-A and F5OS-C systems, potentially resulting in a full compromise of the affected security boundary.
Vulnerability
This vulnerability involves an improper neutralization of directives in dynamically evaluated code (CWE-95). It requires an attacker to have authenticated local access to the system to trigger the escalation.
Business impact
Successful exploitation of this vulnerability allows an authenticated user to bypass security boundaries and achieve elevated privileges, leading to unauthorized access to sensitive system functions. With a CVSS score of 8.8, this flaw represents a significant risk to the integrity and confidentiality of the affected network infrastructure. Organizations may face unauthorized data access or complete system takeover if the attacker successfully leverages this privilege escalation.
Remediation
Immediate Action: Review the official F5 security advisory K000156771 to identify the specific firmware versions containing the security fix and schedule an upgrade for all affected F5OS-A and F5OS-C appliances.
Proactive Monitoring: Monitor system logs for unauthorized configuration changes or unusual command execution patterns originating from low-privileged user accounts.
Compensating Controls: Restrict local system access to authorized administrative personnel only and enforce the principle of least privilege for all user accounts on the appliance.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the potential for privilege escalation within critical network infrastructure, administrators must treat this vulnerability with urgency. Apply the vendor-supplied patches as soon as they become available to ensure the security boundary is restored and the risk of unauthorized administrative access is mitigated.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.