Remote Command Injection Vulnerability in F5 Appliance Mode
CVE-2025-23239
8.5HIGH
Summary
An authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint when F5 appliances operate in Appliance mode. A successful exploitation of this vulnerability could allow attackers to execute unauthorized commands, potentially crossing a security boundary and leading to further compromises in the system's integrity.
Affected Version(s)
BIG-IP 17.1.1 < 17.1.2
BIG-IP 16.1.0
BIG-IP 15.1.0
References
CVSS V4
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
F5