F5 Releases Quarterly Security Notification (February 2025) Affecting BIG-IP Products
One of the 13 high impact advisories addresses the command injection vulnerability CVE-2025-20029, which could lead to arbitrary system command execution
Summary
One of the 13 high impact advisories addresses the command injection vulnerability CVE-2025-20029, which could lead to arbitrary system command execution
Affected platforms
The following platforms are known to be affected:
The following platforms are also known to be affected:
- NGINX Plus
- NGINX Open Source
Threat details
Proof-of-concept released for CVE-2025-20029
A proof-of-concept has been released for the vulnerability CVE-2025-20029. Exploitation is considered more likely.
Introduction
F5 has released an overview of vulnerabilities for some of their networking products, including BIG-IP and BIG-IP Next. The overview of security advisories addresses 13 vulnerabilities rated as high impact, 3 rated as medium impact, and 1 as low impact.
One of the high impact advisories concerns the command injection vulnerability CVE-2025-20029, which has a CVSSv4 score 8.7 and could allow an authenticated attacker to execute arbitrary system commands.
Threat updates
Date | Update |
---|---|
24 Feb 2025 | Cyber Alert updated to reflect the release of a proof-of-concept for CVE-2025-20029 |
Remediation advice
Affected organisations are strongly encouraged to review K000149540: Quarterly Security Notification (February 2025) and apply any relevant updates or mitigation.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 24 February 2025 1:31 pm