CVE-2025-53521
Last modified
CVE-2025-53521 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.. CISA has confirmed active exploitation in the wild. EPSS estimates a 2.25% chance of exploitation in the next 30 days.
Description
When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Ip Access Policy Manager | >= 15.1.0, < 15.1.10.8 |
| F5 | Big-Ip Access Policy Manager | >= 16.1.0, < 16.1.6.1 |
| F5 | Big-Ip Access Policy Manager | >= 17.1.0, < 17.1.3 |
| F5 | Big-Ip Access Policy Manager | >= 17.5.0, < 17.5.1.3 |
References
- https://my.f5.com/manage/s/article/K000156741Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-53521US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-53521?
How severe is CVE-2025-53521?
How do I fix CVE-2025-53521?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-53516A reflected cross-site scripting (xss) vulnerability exists …6.1
- CVE-2025-53517Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2025-53518An integer overflow vulnerability exists in the ABF parsing …9.8
- CVE-2025-53519A vulnerability exists in Advantech iView versions prior to …5.4
- CVE-2025-5352A critical stored Cross-Site Scripting (XSS) vulnerability e…9.6
- CVE-2025-53520The affected product allows firmware updates to be downloade…8.8
- CVE-2025-53522Movable Type contains an issue with use of less trusted sour…6.9
- CVE-2025-53523Stored cross-site scripting vulnerabilities exist in GroupSe…5.4
- CVE-2025-53524Fuji Electric Monitouch V-SFT-6 is vulnerable to an out-of-b…8.4
- CVE-2025-53525WeGIA is a web manager for charitable institutions. A Reflec…6.1
- CVE-2025-53526WeGIA is a web manager for charitable institutions. An XSS I…6.1
- CVE-2025-53527WeGIA is a web manager for charitable institutions. A Time-B…9.8
Are you affected by CVE-2025-53521?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
