CVE-2025-31644

When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Configurations

No configuration.

History

08 May 2025, 14:39

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-07 22:15

Updated : 2025-05-08 14:39


NVD link : CVE-2025-31644

Mitre link : CVE-2025-31644

CVE.ORG link : CVE-2025-31644


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')