Privilege Escalation Vulnerability in F5OS Systems by F5 Networks
CVE-2025-61955

8.5HIGH

Key Information:

Vendor

F5

Vendor
CVE Published:
15 October 2025

Badges

đź“° News Worthy

What is CVE-2025-61955?

A vulnerability in F5OS-A and F5OS-C systems allows an authenticated attacker with local access to escalate their privileges. This may result in the attacker crossing established security boundaries, potentially leading to unauthorized access and manipulation of sensitive data. It is important to note that versions of the software that have reached End of Technical Support (EoTS) are not subject to this evaluation.

Affected Version(s)

F5OS - Appliance 1.8.0 < 1.8.3

F5OS - Appliance 1.5.0 < 1.5.4

F5OS - Chassis 1.8.0 < 1.8.2

News Articles

Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities

A nation-state actor stole BIG-IP source code and information on undisclosed vulnerabilities from F5. We explain what sets this theft apart from others.

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • đź“°

    First article discovered by Unit 42

  • Vulnerability published

  • Vulnerability Reserved

Credit

F5
.