← Back to browse · API

CVE-2025-31644

Severity
HIGH
CVSS
8.5
EPSS
0.23906
Risk score
42.37
CISA KEV
No
PoC
No
Published
2025-05-07
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-13936, GHSA-2MQ5-VGX2-CQ4H
Products
F5:BIG-IP 15.1.0 <15.1.10.7, F5:BIG-IP 16.1.0 <16.1.6, F5:BIG-IP 17.1.0 <17.1.2.2
Sources
euvd EUVD-2025-13936

Description

When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

References