Umbra Wiki cve cve/CVE-2025-53521
Back to wiki

CVE-2025-53521 — F5 BIG-IP Stack-Based Buffer Overflow Vulnerability

provenance: imported · CVE: CVE-2025-53521

CVE-2025-53521: F5 BIG-IP Stack-Based Buffer Overflow Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project F5
Product BIG-IP
Date added 2026-03-27
Due date 2026-03-30
Ransomware campaign use Unknown

Description

F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.

Required action (CISA)

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Notes

Please adhere to F5’s guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible F5 products affected by this vulnerability. For more information please see: https://my.f5.com/manage/s/article/K000156741 ; https://my.f5.com/manage/s/article/K000160486 ; https://my.f5.com/manage/s/article/K11438344 ; https://nvd.nist.gov/vuln/detail/CVE-2025-53521

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-53521
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog