CVE-2025-61960

7.5

F5 · BIG-IP

A NULL pointer dereference in the F5 BIG-IP APM Traffic Management Microkernel (TMM) allows unauthenticated remote attackers to cause a denial-of-service condition via crafted traffic.

Executive summary

A critical denial-of-service vulnerability in F5 BIG-IP APM allows unauthenticated remote attackers to crash the Traffic Management Microkernel, resulting in significant service disruption.

Vulnerability

This vulnerability is a NULL pointer dereference (CWE-476) occurring when a per-request policy is active on a portal access virtual server. An unauthenticated attacker can trigger this flaw by sending specific, crafted traffic to the affected endpoint, leading to an immediate termination of the TMM process.

Business impact

The exploitation of this vulnerability results in a complete denial-of-service for the affected BIG-IP device. Given a CVSS score of 7.5, this high-severity flaw poses a substantial risk to business continuity, as it can be triggered remotely without authentication, potentially rendering critical network infrastructure or application delivery platforms unavailable to legitimate users.

Remediation

Immediate Action: Administrators must upgrade F5 BIG-IP instances to the fixed versions identified in the official F5 security advisory K000156597.

Proactive Monitoring: Security teams should monitor system logs for frequent TMM process restarts or unexpected service interruptions that may indicate exploitation attempts.

Compensating Controls: If immediate patching is not feasible, restrict access to the affected virtual server endpoints to trusted IP addresses only, or disable the vulnerable per-request policy configuration if business requirements allow.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the ease of exploitation and the significant impact on network availability, this vulnerability should be treated as a high priority for remediation. Organizations using F5 BIG-IP APM in the affected version ranges must schedule maintenance windows to apply the necessary patches immediately to prevent potential service downtime caused by malicious actors.

More F5 CVEs

Sources

Originally found and disclosed by F5, per the CVE Program record.