VulnerabilityBleeping Computer
9.8 — CRITICAL
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Hackers have breached F5 BIG-IP APM devices to deploy a Linux rootkit, allowing for the interception of PHP file loading and injection of a fileless web shell into memory, potentially leading to remote code execution and elevated privileges.
⚙️Technical Details
💥Impact Assessment
Severity: Critical
Who Is at Risk
Organizations with F5 BIG-IP APM environments, particularly those using Apache on these systems
🛡️Recommended Actions
1Investigate unusual POST requests to targeted .php3 endpoints and PHP responses combining HTTP 201 with a text/css content type
2Monitor Apache workers reading /proc/self/maps, changing libphp memory protections, creating /run/bigtlog.pipe, or launching /bin/bash
3Implement additional security measures, such as enabling SELinux configurations and using secure credentials
📦Affected Products
F5 Big-Ip Access Policy ManagerF5 Big-IP Access Policy Manager
🔐NVD Verified DataVERIFIED
CVE-2025-53521 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-121
Affected Products (CPE)
F5 Big-Ip Access Policy Manager
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
