

Multiple Zohocorp ManageEngine Products Vulnerabilities
October 22, 2025
North Korea-Linked Konni APT Group – Active IOCs
October 22, 2025
Multiple Zohocorp ManageEngine Products Vulnerabilities
October 22, 2025
North Korea-Linked Konni APT Group – Active IOCs
October 22, 2025Severity
Medium
Analysis Summary
CVE-2025-58424 CVSS:3.7
F5 BIG-IP could allow a remote attacker to bypass security restrictions, caused by predictability problems.
CVE-2025-59781 CVSS:7.5
F5 BIG-IP is vulnerable to a denial of service, caused by an increase in memory resource utilization flaw when DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server.
CVE-2025-46706 CVSS:7.5
F5 BIG-IP is vulnerable to a denial of service, caused by an increase in memory resource utilization due to a flaw when an iRule containing the HTTP::respond command is configured on a virtual server.
CVE-2025-58153 CVSS:5.9
F5 BIG-IP is vulnerable to a denial of service, caused by a lockup of the HSB in hardware systems with a High-Speed Bridge (HSB) under undisclosed traffic conditions.
CVE-2025-48008 CVSS:7.5
F5 BIG-IP is vulnerable to a denial of service, caused by a way to terminate Traffic Management Microkernel (TMM), when a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server.
CVE-2025-58474 CVSS:5.3
F5 BIG-IP is vulnerable to a denial of service, caused by an allocation of resources without limits or throttling flaw.
CVE-2025-59478 CVSS:7.5
F5 BIG-IP is vulnerable to a denial of service, caused by a way to terminate Traffic Management Microkernel (TMM), when protection profile is configured on a virtual server.
CVE-2025-59269 CVSS:6.1
F5 BIG-IP is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the Configuration utility page.
CVE-2025-59268 CVSS:5.3
F5 BIG-IP could allow a remote attacker to obtain sensitive information, caused by a configuration utility vulnerability.
CVE-2025-53474 CVSS:7.5
F5 BIG-IP is vulnerable to a denial of service, caused by a buffer overflow flaw.
Impact
- Denial of Service
- Security Bypass
- Cross-Site Scripting
- Information Disclosure
Indicators of Compromise
CVE
- CVE-2025-58424
- CVE-2025-59781
- CVE-2025-46706
- CVE-2025-58153
- CVE-2025-48008
- CVE-2025-58474
- CVE-2025-59478
- CVE-2025-59269
- CVE-2025-59268
- CVE-2025-53474
Affected Vendors
- F5
Affected Products
- F5 BIG-IP 17.5.0
- F5 BIG-IP - 15.1.0 - 15.1.10
- F5 BIG-IP Next CNF - 1.1.0 - 1.4.0
- F5 BIG-IP Next SPK - 1.7.0 - 1.9.2
- F5 BIG-IP - 17.1.0 - 17.1.2
- F5 BIG-IP - 16.1.0 - 16.1.5
- F5 BIG-IP Next CNF - 1.1.0 - 1.4.1
- F5 NGINX App Protect WAF 4.5.0
- F5 NGINX App Protect WAF 4.6.0
- F5 BIG-IP AFM - 17.1.0 - 17.1.2 - 17.5.0
- F5 BIG-IP AFM - 15.1.0 - 15.1.10
Remediation
Refer to F5 Networks Security Advisory for patch, upgrade, or suggested workaround information.








