CVE-2025-46265

On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher privilege F5OS roles. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Link Resource
https://my.f5.com/manage/s/article/K000139503 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:f5:f5os-a:1.5.1:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-c:*:*:*:*:*:*:*:*

History

21 Oct 2025, 18:01

Type Values Removed Values Added
CPE cpe:2.3:o:f5:f5os-c:*:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-a:1.5.1:*:*:*:*:*:*:*
First Time F5 f5os-c
F5
F5 f5os-a
References () https://my.f5.com/manage/s/article/K000139503 - () https://my.f5.com/manage/s/article/K000139503 - Vendor Advisory

08 May 2025, 14:39

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-07 22:15

Updated : 2025-10-21 18:01


NVD link : CVE-2025-46265

Mitre link : CVE-2025-46265

CVE.ORG link : CVE-2025-46265


JSON object : View

Products Affected

f5

  • f5os-a
  • f5os-c
CWE
CWE-863

Incorrect Authorization