CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2025-53521

CVSS 9.3v4.0pub. 2025-10-15upd. 2026-04-02

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

🤖 AI Analysis
How it works

The vulnerability is classified as CWE-121 (stack-based buffer overflow). When an APM access policy is configured on a BIG-IP virtual server, specially crafted malicious network traffic can overflow a stack buffer, leading to control flow hijacking of the process. The attack requires no authentication, user interaction, or special preconditions — an attacker only needs network access to the interface served by the vulnerable virtual server.

Impact

An attacker can achieve remote code execution (RCE) on an F5 BIG-IP device, which in practice means complete takeover of the device, including potential access to managed network traffic, user authentication credentials using APM, and internal infrastructure.

Mitigation & patch

Immediately apply patches available from the vendor according to the official F5 article K000156741 (https://my.f5.com/manage/s/article/K000156741). Until the patch is deployed, consider restricting network access to virtual servers with APM configuration to trusted IP addresses only and monitor anomalous traffic directed to these services.

Who is affected

F5 BIG-IP Access Policy Manager (APM) — versions specified in vendor references (versions under technical support); the virtual server must have an APM access policy configured. Versions that have reached end of technical support (EoTS) are not covered by this assessment.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • F5 Big Ip Access Policy Manager

    APP
    F5
    15.1.0 – 15.1.10.8 (excl.)16.1.0 – 16.1.6.1 (excl.)17.1.0 – 17.1.3 (excl.)17.5.0 – 17.5.1.3 (excl.)

CISA KEV — detailsi

Vendori
F5
Producti
BIG-IP
Added to KEVi
March 27, 2026
Remediation deadline (US Federal)i
March 30, 2026(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 30 marca 2026
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2023-46747CRITICAL9.8⚠ KEVPL ✓same product

F5 BIG-IP: Obejście uwierzytelnienia i zdalne wykonanie poleceń (RCE)

CVE-2022-1388CRITICAL9.8⚠ KEVPL ✓same product

F5 BIG-IP: Pominięcie uwierzytelnienia iControl REST (RCE)

CVE-2021-22991CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w TMM URI normalization F5 BIG-IP — DoS/RCE

CVE-2021-22986CRITICAL9.8⚠ KEVPL ✓same product

F5 BIG-IP/BIG-IQ iControl REST — nieuwierzytelniony RCE

CVE-2020-5902CRITICAL9.8⚠ KEVPL ✓same product

F5 BIG-IP TMUI — krytyczny RCE przez path traversal (CVE-2020-5902)