CVE-2025-31644
massAuthenticated Command Injection in F5 BIG-IP (Appliance Mode)
CVE-2025-31644 is a command injection flaw (CWE-77) in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that is exposed when a BIG-IP system is running in Appliance mode. An authenticated attacker who already holds the Administrator role on the device can trigger the flaw by issuing a crafted command through the affected interface. A successful exploit lets the attacker execute arbitrary system commands on the underlying operating system, crossing the intended security boundary between the administrative control plane and the system. Affected organizations are those running any of the broad set of BIG-IP modules (e.g., LTM-adjacent services such as APM, ASM, AFM, AWAF, DNS, and others) in Appliance mode on software versions still within technical support; versions past End of Technical Support (EoTS) were not evaluated. As of now there is no known exploitation in the wild and no public proof-of-concept, but the EPSS score of 26.5% (98th percentile) indicates a relatively high probability of exploitation within the next 30 days.
What to do: Inventory all BIG-IP systems and identify which run in Appliance mode, then upgrade to a fixed release listed in the F5 security advisory for CVE-2025-31644, noting that systems on EoTS software versions must move to a supported release to receive patches. Until patching is complete, restrict iControl REST and tmsh access to trusted administrators only, limit exposure of management interfaces to the internet, and review admin accounts for unnecessary Administrator-role assignments. Watch for updates to F5's advisory and KEV listings given the elevated EPSS score, and monitor management-plane logs for unexpected command activity.
| f5 BIG-IP Access Policy Manager | — |
| f5 BIG-IP Advanced Firewall Manager | — |
| f5 BIG-IP Advanced Web Application Firewall | — |
| f5 BIG-IP Analytics | — |
| f5 BIG-IP Application Acceleration Manager | — |
| f5 BIG-IP Application Security Manager | — |
| f5 BIG-IP Application Visibility and Reporting | — |
| f5 BIG-IP Automation Toolchain | — |
| f5 BIG-IP Carrier-Grade NAT | — |
| f5 BIG-IP Container Ingress Services | — |
| f5 BIG-IP DDoS Hybrid Defender | — |
| f5 BIG-IP Domain Name System | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- Vendors
- f5
- Products
- big-ip access policy manager, big-ip advanced firewall manager, big-ip advanced web application firewall, big-ip analytics, big-ip application acceleration manager, big-ip application security manager, big-ip application visibility and reporting, big-ip automation toolchain, big-ip carrier-grade nat, big-ip container ingress services, big-ip ddos hybrid defender, big-ip domain name system
- Weakness
- CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X