CISA aggiunge la falla RCE di F5 BIG‑IP APM al KEV
F5 BIG-IP Access Policy Manager aveva una falla inizialmente etichettata come un problema DoS cinque mesi fa. Nuove prove mostrano che gli attaccanti possono eseguire codice come root senza autenticarsi, quindi CISA ha aggiunto CVE-2025-53521 alla sua lista Known Exploited Vulnerabilities e ha innalzato la gravità a CVSS 9.8.
CVSS 9.8 CRITICAL: when a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code… EPSS 2% (82º percentile).
Data di correzione federale CISA 30 mar · data superata
5-month-old F5 BIG-IP DoS bug becomes critical RCE exploited in the wild
Reclassified as a remote code execution flaw, the F5 BIG-IP APM vulnerability has been upgraded to CVSS 9.8, requiring immediate patching and compromise assessment.
F5 BIG-IP Vuln Reclassified as RCE, Under Exploitation
CVE-2025-53521 was first disclosed in October as a high-severity denial-of-service (DoS) flaw, but new information reveals the bug is much more dangerous.