CVE-2025-53521 – Critical Remote Code Execution in F5 BIG‑IP Access Policy Manager (APM)

CVE-2025-53521 is a Critical remote code execution (RCE) vulnerability in F5 BIG‑IP Access Policy Manager (APM) that requires no authentication and is currently being actively exploited in the wild. The flaw has been added to the CISA KEV catalog, triggering a federal patch deadline of March 30 2026.

Key Takeaways

  • CVE-2025-53521 is Critical (CVSS 9.8/9.3) RCE in F5 BIG‑IP APM.
  • The vulnerability is unauthenticated and actively exploited; it appears in the CISA KEV list.
  • All BIG‑IP APM deployments (and related BIG‑IP modules) are at risk.
  • Apply the vendor‑provided patch or implement mitigations immediately.
  • Monitor for suspicious traffic to the REST API endpoint /mgmt/shared/identified-devices/config/device-info.

Overview

The flaw resides in the handling of access‑policy configurations on virtual servers. When a malicious request reaches the APM REST API, the device allocates resources without proper limits (CWE‑770), allowing an attacker to execute arbitrary code on the underlying operating system. The issue affects multiple BIG‑IP modules that share the same APM code base.


Technical Details

  • Vulnerability type: Remote Code Execution (RCE) via unauthenticated HTTP request.
  • Root cause: Allocation of resources without limits (CWE‑770) in the APM access‑policy processing path.
  • Exploitation vector: A crafted request to the APM REST API endpoint /mgmt/shared/identified-devices/config/device-info. Attackers have been observed using a custom user‑agent string CVE-2025-53521-Scanner/1.0.
  • Impact: Full system compromise – attackers can run arbitrary commands, install backdoors, and pivot to other network assets.

Example of a suspicious request (the malicious payload is omitted for brevity):

GET /mgmt/shared/identified-devices/config/device-info HTTP/1.1
Host: <big‑ip‑host>
User-Agent: CVE-2025-53521-Scanner/1.0

Severity & Impact

MetricValue
CVSS v3.19.8 (Critical)
CVSS v4.09.3 (Critical)
CWECWE‑770 (Allocation of Resources Without Limits or Throttling)

The high CVSS scores reflect the unauthenticated nature of the exploit, network‑wide impact, and complete compromise of confidentiality, integrity, and availability.


Affected Products

The vulnerability impacts the F5 BIG‑IP Access Policy Manager component and any BIG‑IP modules that incorporate the same code base, including but not limited to:

  • BIG‑IP Advanced Firewall Manager
  • BIG‑IP Application Security Manager
  • BIG‑IP Global Traffic Manager
  • BIG‑IP SSL Orchestrator

For the complete list of affected products and version ranges, see the detailed CVE page: https://vulnsocial.com/cve/CVE-2025-53521.


Actionable Insights – What to Watch

  • Network scanning: Look for repeated GET requests to /mgmt/shared/identified-devices/config/device-info from external IPs.
  • User‑Agent indicator: CVE-2025-53521-Scanner/1.0 appears in known exploit traffic.
  • Log anomalies: Sudden spikes in traffic to the APM REST API, especially from unauthenticated sources.
  • IDS/IPS signatures: Deploy signatures that flag the above endpoint and user‑agent pattern.
  • Threat intel feeds: Follow the VulnSocial CVE page for live exploitation signals: https://vulnsocial.com/cve/CVE-2025-53521.

Remediation & Mitigation

  1. Identify your BIG‑IP version and confirm whether the vendor patch is available.
  2. Apply the official F5 patch as described in the vendor advisory (https://my.f5.com/manage/s/article/K000156741). This is the preferred remediation.
  3. If patching cannot be performed immediately, block inbound traffic to the APM REST API endpoint from untrusted networks (e.g., firewall rule restricting /mgmt/shared/identified-devices/*).
  4. disable any unnecessary access‑policy configurations on virtual servers.
  5. Enable detailed logging for the APM REST API and set up alerts for the suspicious user‑agent and endpoint.
  6. Compliance: Federal agencies must complete remediation by the CISA‑mandated deadline of March 30 2026 (see CISA KEV guidance).

Bottom Line

CVE-2025-53521 is a Critical unauthenticated RCE flaw in F5 BIG‑IP Access Policy Manager that is actively exploited worldwide. Immediate patch deployment or effective network‑level mitigations are essential to prevent full system compromise.


References


#CVE #CVE202553521 #Critical #RCE #F5 #BIGIP #CISAKEV #RemoteCodeExecution #NetworkSecurity