← Back to CVE List
Vulnerability Intelligence Report
BigIP APM Vulnerability

CVE-2025-53521

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:2.25%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-121 ↗CWE-121 Stack-based Buffer Overflow

Affected Products & Versions

Vendor Product Affected Versions
F5 BIG-IP 17.5.0 < 17.5.1.3 (affected), 17.1.0 < 17.1.3 (affected), 16.1.0 < 16.1.6.1 (affected), 15.1.0 < 15.1.10.8 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
2.246%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityF5, Inc. · Vendor · USA
Reserved2025-10-03T23:04:38
Published2025-10-15T13:55:52
Patch Date2025-10-15
Last Updated2026-03-31T16:04:27

LINK COPIED TO CLIPBOARD