RULE(RULE ID:338978)

Rule General Information
Release Date: 2025-05-28
Rule Name: F5 BIG-IP Remote Code Execution Vulnerability (CVE-2025-31644)
Severity:
CVE ID:
Rule Protection Details
Description: When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://my.f5.com/manage/s/article/K000148591
Solutions
Please refer to announcements or patches release by the vendor: https://clouddocs.f5.com/api/icontrol-rest/