Cyber Posture

CVE-2025-20029

High

Published: 05 February 2025

Published
05 February 2025
Modified
21 October 2025
KEV Added
Patch
CVSS Score 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.6618 98.5th percentile
Risk Priority 57 60% EPSS · 20% KEV · 20% CVSS

Description

Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an authenticated attacker to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Security Summary

CVE-2025-20029 is a command injection vulnerability (CWE-78) present in the iControl REST interface and the BIG-IP TMOS Shell (tmsh) save command of F5 BIG-IP systems. Published on 2025-02-05, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), reflecting high severity due to its potential for significant impact. Software versions that have reached End of Technical Support (EoTS) are not evaluated for this issue.

An authenticated attacker with low privileges (PR:L) can exploit the vulnerability remotely over the network (AV:N) with low attack complexity (AC:L) and no user interaction (UI:N). Exploitation enables the execution of arbitrary system commands on the affected BIG-IP system, granting high impacts across confidentiality, integrity, and availability (C:H/I:H/A:H).

Mitigation details, including available patches, are outlined in the F5 security advisory at https://my.f5.com/manage/s/article/K000148587.

Details

CWE(s)
CWE-78

Affected Products

f5
big-ip access policy manager
15.1.0 — 15.1.10.6 · 16.1.0 — 16.1.5.2 · 17.1.0 — 17.1.2.1
f5
big-ip advanced firewall manager
15.1.0 — 15.1.10.6 · 16.1.0 — 16.1.5.2 · 17.1.0 — 17.1.2.1
f5
big-ip advanced web application firewall
15.1.0 — 15.1.10.6 · 16.1.0 — 16.1.5.2 · 17.1.0 — 17.1.2.1
f5
big-ip analytics
15.1.0 — 15.1.10.6 · 16.1.0 — 16.1.5.2 · 17.1.0 — 17.1.2.1
f5
big-ip application acceleration manager
15.1.0 — 15.1.10.6 · 16.1.0 — 16.1.5.2 · 17.1.0 — 17.1.2.1
f5
big-ip application security manager
15.1.0 — 15.1.10.6 · 16.1.0 — 16.1.5.2 · 17.1.0 — 17.1.2.1
f5
big-ip application visibility and reporting
15.1.0 — 15.1.10.6 · 16.1.0 — 16.1.5.2 · 17.1.0 — 17.1.2.1
f5
big-ip automation toolchain
15.1.0 — 15.1.10.6 · 16.1.0 — 16.1.5.2 · 17.1.0 — 17.1.2.1
f5
big-ip carrier-grade nat
15.1.0 — 15.1.10.6 · 16.1.0 — 16.1.5.2 · 17.1.0 — 17.1.2.1
f5
big-ip container ingress services
15.1.0 — 15.1.10.6 · 16.1.0 — 16.1.5.2 · 17.1.0 — 17.1.2.1
+11 more product configuration(s) — see NVD for full list

References