CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation
嗯,用户让我帮忙总结一篇文章,控制在100字以内,而且不需要特定的开头。首先,我需要仔细阅读文章内容,抓住关键点。 文章主要讲的是F5 BIG-IP APM的一个严重漏洞CVE-2025-53521,评分9.3,允许远程代码执行。CISA已经将其加入已知被利用漏洞目录。F5最初认为这是一个DoS漏洞,后来重新分类为RCE,并提供了检测指标和修复版本。影响的版本包括17.5.0到15.1.0等,修复版本已经发布。FCEB机构需要在3月30日前完成修复。 接下来,我需要将这些信息浓缩到100字以内。确保涵盖漏洞名称、影响、评分、CISA的行动、F5的修正、检测指标、修复版本以及修复期限。 可能的结构:F5 BIG-IP APM被发现有严重漏洞CVE-2025-53521(CVSS 9.3),允许远程代码执行。CISA已将其列为已知被利用漏洞。F5修正了分类并提供了检测指标和修复版本。影响多个版本,需在指定日期前完成修复。 这样应该能涵盖所有关键点,并且简洁明了。 </think> 美国网络安全和基础设施安全局(CISA)将影响F5 BIG-IP APM的关键漏洞CVE-2025-53521(CVSS v4评分9.3)列为已知被利用漏洞,该漏洞可导致远程代码执行。F5重新分类此漏洞并提供检测指标和修复版本以应对活跃攻击。 2026-3-28 07:7:0 Author: thehackernews.com(查看原文) 阅读量:3 收藏

Vulnerability / Network Security

F5 BIG-IP APM Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw impacting F5 BIG-IP Access Policy Manager (APM) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerability in question is CVE-2025-53521 (CVSS v4 score: 9.3), which could allow a threat actor to achieve remote code execution.

"When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE)," according to a description of the flaw in CVE.org.

While the shortcoming was initially categorized and remediated as a denial-of-service (DoS) vulnerability with a CVSS v4 score of 8.7, F5 said it has been reclassified as a case of RCE in light of "new information obtained in March 2026."

The company has since updated its advisory to confirm that the vulnerability "has been exploited in the vulnerable BIG-IP versions." It did not share any additional details on who may be behind the exploitation activity.

However, F5 shared a number of indicators that can be used to assess if the system has been compromised -

  • File-related indicators -
    • Presence of /run/bigtlog.pipe and/or /run/bigstart.ltm.
    • Mismatch of file hashes when compared to known good versions of /usr/bin/umount and/or /usr/sbin/httpd.
    • Mismatch of file sizes or timestamps when compared to known good versions of /usr/bin/umount and/or /usr/sbin/httpd.
    • Each release and EHF may have different file sizes and timestamps.
  • Log-related indicators -
    • An entry in "/var/log/restjavad-audit.<NUMBER>.log" showing a local user accessing the iControl REST API from localhost.
    • An entry in "/var/log/auditd/audit.log.<NUMBER>" showing a local user accessing the iControl REST API from localhost to disable SELinux.
    • Log messages in "/var/log/audit" show the results of a command being run in the audit log.
  • Other TTPs observed include -
    • Modifications to the underlying components that the system integrity checker, sys-eicheck, relies on, resulting in a failure of the tool, specifically /usr/bin/umount and/or /usr/sbin/httpd, indicating unexpected changes to the system software as mentioned above.
    • HTTP/S traffic from the BIG-IP system that contains HTTP 201 response codes and CSS content-type to disguise the attacker's activities.
    • Changes to the following three files, although their presence alone does not signal a security issue -
      • /var/sam/www/webtop/renderer/apm_css.php3
      • /var/sam/www/webtop/renderer/full_wt.php3
      • /var/sam/www/webtop/renderer/webtop_popup_css.php3

"We have observed cases of webshell being written to disk; however, the webshells have been observed to work in memory only, meaning the files listed above might not be modified," F5 cautioned.

The issue impacts the following versions -

  • 17.5.0 - 17.5.1 (Fixed in version 17.5.1.3)
  • 17.1.0 - 17.1.2 (Fixed in version 17.1.3)
  • 16.1.0 - 16.1.6 (Fixed in version 16.1.6.1)
  • 15.1.0 - 15.1.10 (Fixed in version 15.1.10.8)

In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies have been given until March 30, 2026, to apply the fixes to secure their networks.

"When F5 CVE-2025-53521 first emerged last year as a denial-of-service issue, it didn't immediately signal urgency, and many system administrators likely prioritized it accordingly," watchTowr CEO and founder Benjamin Harris said in a statement shared with The Hacker News.

"Fast forward to today's big 'yikes' moment: the situation has changed significantly. What we're observing now is pre-auth remote code execution and evidence of in-the-wild exploitation, with a CISA KEV listing to back it up. That's a very different risk profile than what was initially communicated."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/03/cisa-adds-cve-2025-53521-to-kev-after.html
如有侵权请联系:admin#unsafe.sh