Remote Command Injection Vulnerability in F5 Appliance Mode
CVE-2025-23239

8.5HIGH

Key Information:

Vendor
F5
Status
Vendor
CVE Published:
5 February 2025

Summary

An authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint when F5 appliances operate in Appliance mode. A successful exploitation of this vulnerability could allow attackers to execute unauthorized commands, potentially crossing a security boundary and leading to further compromises in the system's integrity.

Affected Version(s)

BIG-IP 17.1.1 < 17.1.2

BIG-IP 16.1.0

BIG-IP 15.1.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

F5
.