CVE-2025-53521
BigIP APM Vulnerability
Description
When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
In plain language
AI Act nowCVE-2025-53521 is a weakness in F5 BIG-IP that can let an attacker run code remotely without logging in, and it can also knock the system offline—if you use BIG-IP APM with an access policy on a virtual server, you should act now.
CVE-2025-53521 is an unauthenticated remote code execution in F5 BIG-IP (APM access policy configured on a virtual server), where crafted network traffic triggers code execution that can lead to denial of service; it is listed in CISA KEV and has been exploited in the wild.
What to do now
- Check whether your F5 BIG-IP device has BIG-IP APM configured with an access policy on a virtual server.
- Determine your current BIG-IP version from the device’s system information screen or your vendor management tooling.
- Upgrade to one of the fixed versions: 17.5.1.3, 17.1.3, 16.1.6.1, or 15.1.10.8 (covers BIG-IP and the listed BIG-IP module names).
- If you cannot patch immediately, follow F5’s mitigations from the vendor remediation article linked in the advisory and restrict/limit exposure of the affected virtual server endpoints as directed by F5.
- After updating, review BIG-IP logs and system indicators for signs of compromise, and confirm the device continues to enforce the expected access-policy configuration.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkitsen·The Hacker News· Exploited RubyGems Chaotic Eclipse
- Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memoryen-us·Help Net Security· Exploited F5 BIG-IP APM malware
- F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scansen·The Hacker News· Exploited F5 BIG-IP APM malware
- Hackers breach F5 BIG-IP APM devices to deploy Linux rootkiten-us·BleepingComputer· Exploited F5 BIG-IP APM malware
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-53521 and every CVE in our database. Create a free account — no credit card required.
Create Free Account