F5 Security Updates – 19 August 2025

F5 has released security updates to address several vulnerabilities affecting multiple F5 products.

The addressed vulnerabilities could allow the attacker to perform denial of service attacks, obtain sensitive information, or gain elevated privileges on the affected products.

Sample of the addressed vulnerabilities:

1. F5 BIG-IP Denial of Service Vulnerability (CVE-2025-52585):

  • CVSS: 7.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial of Service

2. F5 BIG-IP (APM) Privilege Escalation Vulnerability (CVE-2025-48500):

  • CVSS: 7.3
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: Required
  • Consequences: Gain Privileges

Sample of the Affected Products:

  • BIG-IP (all modules) versions from 15.1.0 to 15.1.10.
  • BIG-IP (APM) versions from 17.1.0 to 17.1.2.
  • APM Clients version 7.2.5.
  • BIG-IP Next (all modules) version 20.3.0.
  • BIG-IP Next SPK versions from 1.7.0 to 1.9.2.
  • BIG-IP Next CNF versions from 2.0.0 to 2.0.2.
Vulnerabilities
  • CVE-2025-52585
  • CVE-2025-46405
  • CVE-2025-54809
  • CVE-2025-48500
  • CVE-2025-54500
  • CVE-2025-53859
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

F5 Security Advisory

References