Stack-based buffer overflow in F5 BIG-IP (CVE-2025-53521) — possible remote code execution on an edge device; CVSS 9.8
F5 BIG-IP (the APM module), an edge device handling application delivery and access control, contains a stack-based buffer overflow flaw (CWE-121). An attacker may achieve remote code execution. The CVSS published on NVD is 9.8 (CRITICAL). CISA added it to the KEV on 2026-03-27, due 2026-03-30 (3 days).
Key facts
- CVE IDCVE-2025-53521
- CVSS base score9.8 CRITICAL
- CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Affected (vendor / product)F5 BIG-IP
- CWECWE-121
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2026-03-30 (U.S. federal civilian agencies, BOD 22-01)
Key points
- Stack-based buffer overflow (CWE-121) in F5 BIG-IP (APM module) — possible remote arbitrary code execution.
- The CVSS published on NVD is 9.8 (CRITICAL; AV:N/AC:L/PR:N/UI:N/C:H/I:H/A:H).
- BIG-IP is an edge device handling load balancing, application delivery, and VPN — first to receive outside access.
- Like Citrix NetScaler, seizing an edge device is an entry point to the interior — weighty as the origin of damage.
- CISA added it to the KEV on 2026-03-27, due 2026-03-30 (3 days). The response is updating per F5's guidance.
A stack-based buffer overflow is a defect in which data is written beyond an allocated region on the "stack" a program uses as temporary workspace, corrupting adjacent control information (such as the return address). Exploited precisely, an attacker can hijack the program's flow of execution and run arbitrary code. This is said to be possible in F5 BIG-IP's Access Policy Manager (APM) module.
What matters is that BIG-IP is an "edge device." BIG-IP handles load balancing, application delivery, and remote access (VPN), placed at the internet boundary that first receives access from outside. Like the Citrix NetScaler covered separately on this site, such edge devices are exposed to the internet at all times and, once seized, become the entry point to the interior — a prime target for attackers. Remote code execution on an edge device is extremely weighty as the origin of damage.
The CVSS published on NVD is 9.8 (CRITICAL), the highest tier, with unauthenticated, remote, no-user-interaction conditions met. CISA's short 3-day remediation window underscores the urgency. The response is prompt updating per F5's guidance.
Why it matters
Remote code execution on an edge device ties directly to surrendering the entry point to the internal network — extremely weighty as the origin of damage. The CVSS published on NVD is 9.8 (CRITICAL), with exploitation conditions met. Like Citrix NetScaler, edge devices exposed to the internet are targets, and CISA's 3-day deadline signals urgency. F5 operators should prioritize updating per F5's guidance and reviewing edge-device exposure.
FAQ
What is a stack-based buffer overflow?
Why is an edge device being targeted serious?
What should I do?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).