VendorsF5big-ip_advanced_web_application_firewallall versions
Vulnerabilities

F5 Big-ip Advanced Web Application Firewall

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

195CVEs
CVE-2025-21091
BIG-IP SNMP vulnerability
Published 2025-02-05 · Analyzed
8.7EPSS 0.005
CVE-2025-48008
BIG-IP MPTCP vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-53868
BIG-IP SCP and SFTP vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2023-43746
BIG-IP Appliance mode external monitor vulnerability
Published 2023-10-10 · Modified
8.7EPSS 0.004
CVE-2025-46706
BIG-IP iRules vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-36504
BIG-IP HTTP/2 vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-41433
BIG-IP SIP ALG profile vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-41399
SCTP Vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-41414
BIG-IP HTTP/2 vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2022-25946
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, when running in Appliance mode, an authenticated attacker with Administrator role privilege may be able to bypass Appliance mode restrictions due to a missing integrity check in F5 BIG-IP Guided Configuration. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Published 2022-05-05 · Modified
8.7EPSS 0.004
CVE-2026-40698
iControl REST and TMSH vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.004
CVE-2026-40631
BIG-IP iControl SOAP vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.004
CVE-2026-42924
BIG-IP iControl SOAP vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.004
CVE-2026-41953
BIG-IP Privilege Escalation vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.004
CVE-2025-20045
BIG-IP SIP MRF Vulnerability
Published 2025-02-05 · Analyzed
8.7EPSS 0.004
CVE-2026-32673
BIG-IP scripted monitor vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.004
CVE-2025-59481
BIG-IP iControl REST and tmsh vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-61958
BIG-IP TMSH vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-58071
BIG-IP IPSec vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-61935
BIG-IP Advanced WAF and ASM vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-53474
BIG-IP iRules vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-54858
BIG-IP Advanced WAF and ASM vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-53856
TMM vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-61990
TMM vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-61938
BIG-IP Advanced WAF and ASM bd process vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-59781
BIG-IP DNS cache vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-52585
BIG-IP Client SSL profile vulnerability
Published 2025-08-13 · Analyzed
8.7EPSS 0.003
CVE-2026-32643
BIG-IP and BIG-IQ privilege escalation vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.003
CVE-2026-42406
BIG-IP and BIG-IQ privilege escalation vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.003
CVE-2025-61951
BIG-IP DTLS 1.2 Vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.002
CVE-2024-45844
BIG-IP monitors vulnerability
Published 2024-10-16 · Analyzed
8.6EPSS 0.106
CVE-2026-39459
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
8.6EPSS 0.005
CVE-2025-59483
BIG-IP Configuration utility and tmsh vulnerability
Published 2025-10-15 · Analyzed
8.5EPSS 0.004
CVE-2025-59269
BIG-IP Configuration utility XSS vulnerability
Published 2025-10-15 · Analyzed
8.4EPSS 0.003
CVE-2021-22978
On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all 12.1.x and 11.6.x versions, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of BIG-IP if the victim user is granted the admin role. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-02-12 · Modified
8.3EPSS 0.008
CVE-2026-41217
BIG-IP tmsh vulnerability
Published 2026-05-13 · Analyzed
8.3EPSS 0.002
CVE-2024-41164
BIG-IP MPTCP vulnerability
Published 2024-08-14 · Analyzed
8.2EPSS 0.004
CVE-2025-58096
BIG-IP TMM vulnerability
Published 2025-10-15 · Analyzed
8.2EPSS 0.003
CVE-2021-23012
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of input validation for items used in the system support functionality may allow users granted either "Resource Administrator" or "Administrator" roles to execute arbitrary bash commands on BIG-IP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-05-10 · Modified
8.2EPSS 0.003
CVE-2025-58153
BIG-IP HSB vulnerability
Published 2025-10-15 · Analyzed
8.2EPSS 0.002
← Prev2 / 5Next →