CVE 7.5 HIGH

BIG-IP Next (CNF, SPK, and Kubernetes) vulnerability_CVE-2025-58120

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

When HTTP/2 Ingress is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Basic Information

ID CVE-2025-58120
Source f5
Published Oct 15, 2025 at 13:55

Affected Product

Vendor F5
Product BIG-IP Next SPK
Version 2.0.0
Affected Versions F5 BIG-IP Next SPK 2.0.0
F5 BIG-IP Next SPK 1.9.0
F5 BIG-IP Next SPK 1.8.0
F5 BIG-IP Next SPK 1.7.0
F5 BIG-IP Next CNF 2.0.0
F5 BIG-IP Next CNF 1.1.0
F5 BIG-IP Next for Kubernetes 2.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.