CVE-2025-54809

Severity
8.8HIGH
EPSS
0.0%
top 84.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 13

Description

F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

Affected Packages2 packages

CVEListV5f5/f5_access3.1.03.1.2
NVDf5/f5_access3.1.03.1.2

🔴Vulnerability Details

2
GHSA
GHSA-gqx9-9g2r-r86m: F5 Access for Android before version 32025-08-13
CVEList
F5 Access for Android vulnerability2025-08-13

📋Vendor Advisories

1
F5
CVE-2025-54809: F5 Access for Android before version 32025-08-13
CVE-2025-54809 (HIGH CVSS 8.8) | F5 Access for Android before versio | cvebase.io