CVE-2025-61958
8.7F5 · BIG-IP
An authenticated vulnerability in the F5 BIG-IP iHealth command allows resource administrators to bypass tmsh restrictions and execute commands in a bash shell.
Executive summary
A high-severity authentication-based vulnerability in F5 BIG-IP allows authorized administrators to escape restricted command environments and execute arbitrary commands within a bash shell.
Vulnerability
This flaw involves an improper restriction of operations within the iHealth command, which allows an authenticated attacker possessing a resource administrator role to escape the Traffic Management Shell (tmsh) and gain unauthorized access to the underlying system bash shell.
Business impact
Successful exploitation of this vulnerability permits an attacker to cross security boundaries, potentially leading to full system compromise or unauthorized configuration changes. Given the CVSS score of 8.7, this represents a significant risk to the integrity and availability of network infrastructure managed by BIG-IP devices. Organizations may face severe operational disruption if an attacker leverages this access to manipulate traffic management policies or exfiltrate sensitive system data.
Remediation
Immediate Action: Upgrade to the fixed versions (17.5.1.1, 17.1.3, 16.1.6.1, or 15.1.10.8) as provided in the vendor security advisory.
Proactive Monitoring: Review system access logs for unusual activity involving the iHealth command or unexpected bash shell execution patterns.
Compensating Controls: Strictly enforce the principle of least privilege by auditing and limiting the number of users assigned the resource administrator role.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this flaw necessitates immediate attention, particularly for systems exposed to administrative access. Administrators should prioritize patching the affected BIG-IP instances to the versions specified by F5 to eliminate the risk of privilege escalation. Given the potential for total system impact, verify the integrity of administrative accounts and confirm that all environment-specific mitigations are applied if immediate patching is not possible.
More F5 CVEs
Sources
Originally found and disclosed by F5 acknowledges Australian Cyber Security Centre for bringing this issue to our attention and following the highest stan, per the CVE Program record.