ZeroHour

CVE-2025-31644

mass

Authenticated Command Injection in F5 BIG-IP (Appliance Mode)

CVSS 4.0
8.5 high
EPSS
27%p98
Published
()
Modified
AI analysis

CVE-2025-31644 is a command injection flaw (CWE-77) in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that is exposed when a BIG-IP system is running in Appliance mode. An authenticated attacker who already holds the Administrator role on the device can trigger the flaw by issuing a crafted command through the affected interface. A successful exploit lets the attacker execute arbitrary system commands on the underlying operating system, crossing the intended security boundary between the administrative control plane and the system. Affected organizations are those running any of the broad set of BIG-IP modules (e.g., LTM-adjacent services such as APM, ASM, AFM, AWAF, DNS, and others) in Appliance mode on software versions still within technical support; versions past End of Technical Support (EoTS) were not evaluated. As of now there is no known exploitation in the wild and no public proof-of-concept, but the EPSS score of 26.5% (98th percentile) indicates a relatively high probability of exploitation within the next 30 days.

What to do: Inventory all BIG-IP systems and identify which run in Appliance mode, then upgrade to a fixed release listed in the F5 security advisory for CVE-2025-31644, noting that systems on EoTS software versions must move to a supported release to receive patches. Until patching is complete, restrict iControl REST and tmsh access to trusted administrators only, limit exposure of management interfaces to the internet, and review admin accounts for unnecessary Administrator-role assignments. Watch for updates to F5's advisory and KEV listings given the elevated EPSS score, and monitor management-plane logs for unexpected command activity.

Affected
f5 BIG-IP Access Policy Manager
f5 BIG-IP Advanced Firewall Manager
f5 BIG-IP Advanced Web Application Firewall
f5 BIG-IP Analytics
f5 BIG-IP Application Acceleration Manager
f5 BIG-IP Application Security Manager
f5 BIG-IP Application Visibility and Reporting
f5 BIG-IP Automation Toolchain
f5 BIG-IP Carrier-Grade NAT
f5 BIG-IP Container Ingress Services
f5 BIG-IP DDoS Hybrid Defender
f5 BIG-IP Domain Name System
Estimated exposure
masson the order of hundreds of thousands of BIG-IP deployments (10^5), though the practically exploitable subset is smaller — Historical public internet scans of BIG-IP management interfaces have repeatedly found roughly 300,000+ exposed F5 BIG-IP instances, and the affected CPE list spans nearly the entire BIG-IP module portfolio; however, exploitation requires…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vendors
f5
Products
big-ip access policy manager, big-ip advanced firewall manager, big-ip advanced web application firewall, big-ip analytics, big-ip application acceleration manager, big-ip application security manager, big-ip application visibility and reporting, big-ip automation toolchain, big-ip carrier-grade nat, big-ip container ingress services, big-ip ddos hybrid defender, big-ip domain name system
Weakness
CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news