Vulnerability Intelligence Report
BigIP APM Vulnerability
CVE-2025-53521
When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CISA KEV
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:2.25%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-121 ↗CWE-121 Stack-based Buffer Overflow
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| F5 | BIG-IP | 17.5.0 < 17.5.1.3 (affected), 17.1.0 < 17.1.3 (affected), 16.1.0 < 16.1.6.1 (affected), 15.1.0 < 15.1.10.8 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | F5, Inc. · Vendor · USA |
| Reserved | 2025-10-03T23:04:38 |
| Published | 2025-10-15T13:55:52 |
| Patch Date | 2025-10-15 |
| Last Updated | 2026-03-31T16:04:27 |
Community Chatter & Buzz