Skip to content
COOEY

FAIL › dossier

BIG-IP

PRODUCT

· dossier confidence 50%

BIG-IP, a F5 Networks product, has experienced significant security vulnerabilities, including high-severity remote code execution issues that have been actively exploited.

PROFILE
CategoryNetworking HardwareWhat they doBIG-IP is a series of hardware and software products designed to optimize and control the delivery of network traffic for F5 Networks.
SECURITY POSTURE

The company has faced multiple high-severity vulnerabilities, indicating a need for robust security measures and processes.

Notable failures
  • CVE-2025-53521: High-severity remote code execution vulnerability
  • CVE-2022-1388: Critical remote code execution vulnerability due to missing authentication
  • CVE-2020-5902: Critical remote code execution vulnerability in TMUI
Patterns: Repeated remote code execution vulnerabilities; Lack of proper authentication controls; Active exploitation in the wild
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2026-03-27 CVE-2025-53521 high F5 BIG-IP APM stack-based buffer overflow enables remote code execution and is actively exploited in the wild.
2022-05-10 CVE-2022-1388 critical F5 BIG-IP's missing authentication allowed remote code execution and service disruption, actively exploited in ransomware attacks.
2021-11-03 CVE-2020-5902 critical F5 BIG-IP's TMUI had a critical, actively exploited remote code execution vulnerability in undisclosed pages.
Open questions: How has F5 Networks addressed these vulnerabilities? · What is the current state of security for BIG-IP products?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-26 03:44:37.327384+00:00