CVE-2025-43878 Details
Description
When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may be able to bypass Appliance mode restrictions utilizing system diagnostics tcpdump command utility on a F5OS-C/A system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A vulnerability exists in F5OS-C and F5OS-A systems running in Appliance mode, allowing an authenticated attacker with Administrator or Resource Administrator privileges to bypass Appliance mode restrictions. This is achieved by using the system diagnostics tcpdump command utility. The vulnerability is classified as a control plane issue, with no data plane exposure.
F5 has released an engineering hotfix for this vulnerability in F5OS-C, available for download from the MyF5 Downloads page. For F5OS-A, users can upgrade to version 1.8.0.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000139502 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1286 | Improper Validation of Syntactic Correctness of Input | [email protected] |
| CWE-149 | Improper Neutralization of Quoting Syntax | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 f5os-a | >= 1.5.1, < 1.8.0 |
CPE
Remediation
| |
| f5 f5os-c | >= 1.6.0, <= 1.6.2 |
CPE
Remediation
| |
| f5 r10600 | All versions |
CPE
Remediation
| |
| f5 r10800 | All versions |
CPE
Remediation
| |
| f5 r10900 | All versions |
CPE
Remediation
| |
| f5 r12600-ds | All versions |
CPE
Remediation
| |
| f5 r12800-ds | All versions |
CPE
Remediation
| |
| f5 r12900-ds | All versions |
CPE
Remediation
| |
| f5 r5600 | All versions |
CPE
Remediation
| |
| f5 r5800 | All versions |
CPE
Remediation
| |
| f5 r5900 | All versions |
CPE
Remediation
| |
| f5 velos cx1610 | All versions |
CPE
Remediation
| |
| f5 velos cx410 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 7, 2025 | Initial Analysis | [email protected] |
| May 7, 2025 | New CVE Received | [email protected] |