CVE-2025-53521: F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
How it works
CWE-121 describes a stack-based buffer overflow in which data written past the end of a fixed-size buffer on the call stack can corrupt adjacent memory. In this class of flaw an attacker supplies crafted input that exceeds the allocated buffer, potentially overwriting return addresses or control structures. When the affected code path executes, the corrupted state can redirect execution to attacker-controlled locations, resulting in remote code execution.
Am I affected? How to find it in your systems
Inventory all F5 BIG-IP devices that have the APM module enabled. Review configuration to identify virtual servers and access profiles that use APM features. Confirm the exact software version and hotfix level running on each unit against the vendor advisory, as only specific builds contain the vulnerable code path. Examine logs for anomalous APM-related requests, unexpected process crashes, or memory-related error messages that precede service restarts.
How to remediate
Apply the vendor-supplied update referenced in the official advisory. After patching, verify that the updated build is active on all affected devices and that APM configurations remain functional. For this weakness class, ensure that input-handling paths receive only validated data sizes and that stack protections such as canaries remain enabled in the running image.
If you can't patch immediately
- Place BIG-IP devices behind network segmentation that restricts inbound access to management and APM listener ports to trusted sources only.
- Follow applicable CISA BOD 22-01 guidance for any cloud-hosted instances.
- Disable APM features on virtual servers where the functionality is not required.
- Monitor for exploitation indicators using available telemetry and maintain the option to discontinue use of the product if mitigations cannot be applied.
If your data may have been exposed
Remote code execution on appliances that handle authentication and access decisions can lead to data exposure. Organizations can run a free exposure scan of their domains to check known breach data.
AICompiled with AI assistance from public sources and published under our editorial standards.
Details
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X