cbcvebase.
CVE-2025-53521
published 2025-10-15

CVE-2025-53521: When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions…

PriorityP192critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-03-30
Exploited in the wild
EPSS
2.21%
80.8th percentile
When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected

9 ranges
VendorProductVersion rangeFixed in
f5big-ip>= 15.1.0 < 15.1.10.815.1.10.8
f5big-ip>= 16.1.0 < 16.1.6.116.1.6.1
f5big-ip>= 17.1.0 < 17.1.317.1.3
f5big-ip>= 17.5.0 < 17.5.1.317.5.1.3
f5big-ip_access_policy_manager>= 15.1.0 < 15.1.10.815.1.10.8
f5big-ip_access_policy_manager>= 16.1.0 < 16.1.6.116.1.6.1
f5big-ip_access_policy_manager>= 17.1.0 < 17.1.317.1.3
f5big-ip_access_policy_manager>= 17.5.0 < 17.5.1.317.5.1.3
f5big-ip_apm

Detection & IOCsextracted from sources · hover to see the quote

path/run/bigtlog.pipe
path/run/bigstart.ltm
path/usr/bin/umount
path/usr/sbin/httpd
path/var/sam/www/webtop/renderer/apm_css.php3
path/var/sam/www/webtop/renderer/full_wt.php3
path/var/sam/www/webtop/renderer/webtop_popup_css.php3
url/mgmt/shared/identified-devices/config/device-info
  • Check for presence of anomalous named pipe/socket files /run/bigtlog.pipe and /run/bigstart.ltm on BIG-IP APM systems as indicators of compromise.
  • Verify file hashes, sizes, and timestamps of /usr/bin/umount and /usr/sbin/httpd against known-good baselines; mismatches indicate tampering.
  • Monitor /var/log/restjavad-audit..log for entries showing a local user accessing the iControl REST API from localhost, which is anomalous and indicative of post-exploitation activity.
  • Monitor /var/log/auditd/audit.log for entries showing a local user accessing the iControl REST API from localhost to disable SELinux.
  • Review /var/log/audit for command execution results logged in the audit log as evidence of attacker hands-on-keyboard activity.
  • Run sys-eicheck (system integrity checker) and flag failures specifically against /usr/bin/umount and /usr/sbin/httpd as indicators of unexpected system software modification.
  • Detect attacker C2/exfiltration disguise by hunting for outbound HTTP/S traffic from BIG-IP systems returning HTTP 201 response codes with a CSS content-type header.
  • Webshells observed at .php3 paths under /var/sam/www/webtop/renderer/ may operate in memory only; the files may not be modified on disk, so memory forensics is required in addition to file-based checks.
  • Alert on scanning/reconnaissance activity targeting the F5 BIG-IP REST API endpoint /mgmt/shared/identified-devices/config/device-info, which is being actively probed to fingerprint vulnerable devices.
  • Do not trust UCS backup files for restoration if the compromise time is unknown; UCS files from compromised systems can contain persistent malware.
  • ·The vulnerability is only exploitable when a BIG-IP APM access policy is configured on a virtual server; systems without this configuration are not affected.
  • ·Each BIG-IP release and EHF may have different file sizes and timestamps for the monitored binaries, so baseline comparisons must be version-specific.
  • ·Webshells have been observed operating in memory only; on-disk files at the known webshell paths may not be modified, requiring memory-based detection approaches.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck9.3CRITICAL
cisa9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.