CyberzSOC

Publication detail
← Back to advisories & guidance

2025-037: Multiple Vulnerabilities in F5 Products ↗ source

October 15, 2025 CERT-EU Advisory

Summary

This included access to BIG-IP product development source code and to information related to security vulnerabilities that had not yet been disclosed nor patched. F5 released patches on the same day to address There is currently no known exploitation of these vulnerabilities. CERT-EU strongly recommends to patch affected F5 products as soon as possible. The vulnerability CVE-2025-53868, with a CVSS score of 8.5, is affecting all modules of BIG-IP and could allow a highly privileged authenticated attacker with access to Secure Copy (SCP) protocol and SFTP to bypass Appliance mode restrictions using undisclosed commands. [3] The vulnerability CVE-2025-61955 and CVE-2025-57780, with a CVSS score of 8.5, are affecting F5OS and could allow an authenticated attacker with local access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary. [4,5] The exhaustive list of vulnerabilities can be found in the F5 Quarterly Security Notification.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-57780 8.8 High F5 F5OS - Appliance A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to escalate their privileges.  A succes…
CVE-2025-61955 8.8 High F5 F5OS - Appliance A vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access to escalate their privileges.  A succe…
CVE-2025-53868 8.7 High F5 BIG-IP When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restricti…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.