F5 Security Updates – 13 May 2025

F5 has released security updates to address several vulnerabilities affecting multiple F5 products.

The addressed vulnerabilities could allow the attacker to gain elevated privileges, manipulate files, bypass security restrictions, perform denial of service attacks, or gain access by using SSH key-based authentication to the affected product.

Sample of the addressed vulnerabilities:

1. F5OS Improper Authorization Vulnerability (CVE-2025-46265):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privileges

2. Appliance Mode BIG-IP Vulnerability (CVE-2025-31644):

  • CVSS: 8.7
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Bypass Security
Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

F5 Security Advisory

References