Undisclosed Traffic Vulnerability in F5 Networks Traffic Management Microkernel
CVE-2025-58120

8.7HIGH

What is CVE-2025-58120?

A vulnerability has been identified in the Traffic Management Microkernel of F5 Networks, triggered when HTTP/2 Ingress is configured. The presence of undisclosed traffic can lead to unexpected termination of the microkernel, potentially disrupting service availability. It is important to note that versions of the software that have reached End of Technical Support (EoTS) are not subject to evaluation under this vulnerability.

Affected Version(s)

BIG-IP Next CNF 2.0.0 < 2.0.1

BIG-IP Next CNF 1.1.0

BIG-IP Next for Kubernetes 2.0.0 < 2.1.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

F5
.
CVE-2025-58120 : Undisclosed Traffic Vulnerability in F5 Networks Traffic Management Microkernel