HomeSecurityF5 BIG-IP APM: Critical RCE vulnerability used in attacks

F5 BIG-IP APM: Critical RCE vulnerability used in attacks

A vulnerability that was incorrectly classified as a denial-of-service (DoS) issue in F5 BIG-IP Access Policy Manager (APM) has turned out to be a critical remote code execution (RCE) vulnerability. In fact, the vulnerability is now being actively exploited. Hackers are using it to develop a program malware that runs with root privileges.

F5 BIG-IP

The vulnerability, CVE-2025-53521, was first disclosed in October 2025 as a DoS issue with a CVSS severity rating of 7.5. F5 changed the advisory on Friday, reclassifying it as remote code execution and increasing its rating to CVSS 9.8 based on “new information” it received. On the same day, CISA added the vulnerability to its Known Exploitable Vulnerabilities (KEV) list, and the Netherlands Cybersecurity Center reported that it was actively being exploited.

See also: Vertex AI vulnerability exposes Google Cloud data and files

F5 BIG-IP Access Policy Manager (APM)

BIG-IP APM is F5's secure access solution that enables enterprises, service providers, and government agencies to control authentication, authorization, and VPN access across remote, mobile, and cloud environments. The Shadowserver Foundation currently monitors over 240,000 F5 BIG-IP instances online, but it's unclear how many are running vulnerable versions.

“ When CVE-2025-53521 first emerged last year as a denial-of-service issue, it didn’t immediately raise alarm bells and many system administrators likely didn’t prioritize it ,” Benjamin Harris , CEO of watchTowr, told CSO . “ The situation has now changed significantly. What we’re seeing now is remote code execution before certification, real-world evidence of exploitation, and a CISA KEV listing . This is a very different risk profile than what was initially communicated .”

Patching is only part of the equation, and according to Harris, security teams must now determine whether the vulnerability has already been exploited in their environment.

The vulnerability affects BIG-IP APM versions 17.1.0 to 17.1.2, 17.5.0 to 17.5.1, 16.1.0 to 16.1.6, and 15.1.0 to 15.1.10. F5 has released patches for versions 17.1.3, 17.5.1.3, 16.1.6.1, and 15.1.10.8. The company also published an article with indicators of compromise, attacker TTPs, and malware mitigation guidelines.

See also: CISA: Citrix NetScaler vulnerability in KEV Catalog

F5 BIG-IP APM: Critical RCE vulnerability used in attacks

How the attack works

BIG-IP APM is only affected when configured on a virtual server. This is a limiting factor for attacks, but it is not an uncommon scenario. Successful exploitation gives attackers access root-level and full control of the underlying operating system.

The company is tracking the malware as “c05d5254” and notes that it creates files in /run/bigtlog.pipe and /run/bigstart.ltm and makes changes to system binaries, including /usr/bin/umount and /usr/sbin/httpd. Attackers have also been observed modifying the sys-eicheck utility, which relies on RPM integrity checks to verify executable files on disk.

Log analysis can reveal patterns related to the attack. The user “f5hubblelcdadmin” accessing the iControl REST API from localhost, SELinux disable commands in the auditd logs, and Base64-encoded data written to files following the execution of `/run/bigstart.ltm` all indicate a successful intrusion. F5 also observed that the malicious users were using HTTP 201 response codes with CSS content-type headers to hide the malicious traffic.

See also: Fortinet Forticlient EMS: Critical vulnerability used in attacks

F5 BIG-IP APM: Critical RCE vulnerability used in attacks

Mitigation

Organizations that have applied the October 2025 updates are already protected, as the initial patches also address the RCE vector. The rest should upgrade immediately.

However, organizations should not assume their systems are clean based on patching alone, as backup files from compromised systems may contain copies of the malware. F5 recommends rebuilding configurations from scratch rather than restoring from backup (if the time frame of the breach is uncertain).

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The sys-eicheck utility can detect integrity failures in /usr/bin/umount and /usr/sbin/httpd, although attackers have targeted the components on which this tool relies.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS