CVE Alert: CVE-2025-61935 – F5 – BIG-IP

CVE-2025-61935

HIGHNo exploitation known

When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS v3.1 (7.5)
AV NETWORK · AC LOW · PR NONE · UI NONE · S UNCHANGED
Vendor
F5
Product
BIG-IP
Versions
17.5.0 lt 17.5.1 | 17.1.0 lt 17.1.3 | 16.1.0 lt * | 15.1.0 lt 15.1.10.8
CWE
CWE-252, CWE-252: Unchecked Return Value
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Published
2025-10-15T15:19:46.027Z
Updated
2025-10-16T03:56:43.638Z

AI Summary Analysis

Risk verdict

Why this matters

Most likely attack path

Who is most exposed

Detection ideas

  • BD process termination events or crash dumps in system logs.
  • Unexplained restarts/recoveries of BIG-IP services and increased failover activity.
  • Sudden spikes in 5xx responses behind affected virtual servers.
  • Alerts about policy-related crashes or abnormal resource utilisation (CPU/memory).
  • Unusual traffic patterns targeting WAF/ASM endpoints.

Mitigation and prioritisation

  • Patch to supported versions (e.g., upgrade to 17.5.1+ or corresponding fixed releases; verify other affected branches are updated).
  • If patching is delayed: temporarily disable or quarantine affected ASM policies on critical servers; tighten network access to management interfaces; enable rate limiting and robust input filtering.
  • Plan patching in a controlled change window; test in staging and monitor post-deploy.
  • Ensure VMs/instances are within a supported lifecycle (watch for EoTS notes).

Support Our Work

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

AI APIs OSINT driven New features