F5 BIG-IP Command Injection Vulnerability Let Attackers Execute Arbitrary System Commands

F5 Networks has disclosed a high-severity command injection vulnerability (CVE-2025-31644) in its BIG-IP products running in Appliance mode.  The vulnerability exists in an undisclosed iControl REST endpoint and BIG-IP TMOS Shell (tmsh) command, allowing attackers to bypass Appliance mode security restrictions.  Classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), the […]

The post F5 BIG-IP Command Injection Vulnerability Let Attackers Execute Arbitrary System Commands appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: