Skip to main content

F5 Releases Quarterly Security Notification (February 2025) Affecting BIG-IP Products

One of the 13 high impact advisories addresses the command injection vulnerability CVE-2025-20029, which could lead to arbitrary system command execution

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

One of the 13 high impact advisories addresses the command injection vulnerability CVE-2025-20029, which could lead to arbitrary system command execution


The following platforms are also known to be affected:

  • NGINX Plus
  • NGINX Open Source

Threat details

Proof-of-concept released for CVE-2025-20029

A proof-of-concept has been released for the vulnerability CVE-2025-20029. Exploitation is considered more likely.


Introduction

F5 has released an overview of vulnerabilities for some of their networking products, including BIG-IP and BIG-IP Next. The overview of security advisories addresses 13 vulnerabilities rated as high impact, 3 rated as medium impact, and 1 as low impact.

One of the high impact advisories concerns the command injection vulnerability CVE-2025-20029, which has a CVSSv4 score 8.7 and could allow an authenticated attacker to execute arbitrary system commands.


Threat updates

Date Update
24 Feb 2025 Cyber Alert updated to reflect the release of a proof-of-concept for CVE-2025-20029

Remediation advice

Affected organisations are strongly encouraged to review K000149540: Quarterly Security Notification (February 2025) and apply any relevant updates or mitigation.


Definitive source of threat updates


CVE Vulnerabilities

Last edited: 24 February 2025 1:31 pm