Command Injection in Appliance Mode in F5 BIG-IP (CVE-2025-31644)

Summary

Vulnerability NameCommand Injection in Appliance Mode in F5 BIG-IP (CVE-2025-31644)
Released onMay 13, 2025
Affected ComponentF5 BIG-IP
Affected Version

17.1.0 ≤ F5 BIG-IP < 17.1.2.2

16.1.0 ≤ F5 BIG-IP < 16.1.6

15.1.0 ≤ F5 BIG-IP < 15.1.10.7

Vulnerability TypeCommand injection
Exploitation Condition
  1. User authentication: required.
  2. Precondition: default configurations.
  3. Trigger mode: remote.
Impact

Exploitation difficulty: difficult. Administrator privileges are required to exploit this vulnerability.

Severity: high-risk. This vulnerability may lead to remote code execution.

Official SolutionAvailable

About the Vulnerability

Component Introduction

F5 BIG-IP is an advanced application delivery controller (ADC) and load balancing device developed by F5 Networks. It is a type of network device widely used in large enterprises and data center environments to enhance application performance, availability, security, and scalability.

Vulnerability Description

On May 13, 2025, Sangfor FarSight Labs received notification of the command injection vulnerability in Appliance mode in F5 BIG-IP (CVE-2025-31644), classified as high-risk in threat level.

Specifically, when F5 BIG-IP runs in Appliance mode, a command injection vulnerability exists in TMOS Shell (tmsh) that may allow an authenticated attacker with the administrator role to execute arbitrary system commands, leading to server compromises.

Affected Versions

  • 17.1.0 ≤ F5 BIG-IP < 17.1.2.2
  • 16.1.0 ≤ F5 BIG-IP < 16.1.6
  • 15.1.0 ≤ F5 BIG-IP < 15.1.10.7

Solutions

Remediation Suggestions

How to View the Component Version

You can run the cat VERSION command to view the version of the affected component.

Official Solution

New versions have been officially released to fix the vulnerability. Affected users are advised to update F5 BIG-IP to one of the following versions as needed:

  • F5 BIG-IP 17.1.2.2
  • F5 BIG-IP 16.1.6
  • F5 BIG-IP 15.1.10.7

Download link: https://my.f5.com/manage/s/article/K000148591

Sangfor Solutions

Vulnerability Monitoring

The following Sangfor products support CVE-2025-31644 vulnerability monitoring and can identify affected assets and impact scope in business scenarios through traffic collection:

  • Cyber Command: Monitoring solution available May 21, 2025. Rule ID: 11029220.
  • Sangfor Cyber Guardian Platform: Monitoring solution available May 21, 2025. Rule ID: 11029220.
  • Sangfor XDR: Monitoring solution available May 21, 2025. Rule ID: 11029220.
Vulnerability Prevention

The following Sangfor products can effectively block CVE-2025-31644 exploits:

  • Network Secure: Prevention solution available May 21, 2025. Rule ID: 11029220.
  • Sangfor Web Application Firewall: Prevention solution available May 21, 2025. Rule ID: 11029220.
  • Sangfor Cyber Guardian Platform: Prevention solution available May 21, 2025. Rule ID: 11029220.
  • Sangfor XDR: Prevention solution available May 21, 2025. Rule ID: 11029220.

Timeline

  • May 13, 2025: Sangfor FarSight Labs received notification of the vulnerability.
  • May 13, 2025: Sangfor FarSight Labs released a vulnerability alert.

References

https://my.f5.com/manage/s/article/K000148591

Learn More

Sangfor FarSight Labs researches the latest cyber threats and unknown zero-day vulnerabilities, alerting customers to potential dangers to their organizations, and providing real-time solutions with actionable intelligence.

Listen To This Post

Search

Get in Touch

Get in Touch with Sangfor Team for Business Inquiry

Name
Email Address
Business Phone Number
Tell us about your project requirements

Related Articles

Roundup of Microsoft Patch Tuesday (May 2025)

Date : 15 May 2025
Read Now

CVE-2025-32432: Craft CMS Remote Code Execution

Date : 28 Apr 2025
Read Now

CVE-2025-31324: SAP NetWeaver Remote Code Execution

Date : 28 Apr 2025
Read Now

See Other Product

Sangfor Omni-Command
Replace your Enterprise NGAV with Sangfor Endpoint Secure
SASE ROI Calculator - Assess Sangfor SASE’s Total Economic Impact
Cyber Command - NDR Platform
Endpoint Secure
Internet Access Gateway (IAG)