CVE-2025-53521: F5 BIG-IP APM Unauthenticated Remote Code Execution via Stack-based Buffer Overflow
CVE-2025-53521 (TL-2026-0307) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-04-01. It is attributed to UNC5221 (China) with high confidence, affects F5 BIG-IP Access Policy Manager (APM), references 1 CVE (CVE-2025-53521), maps to 24 MITRE ATT&CK techniques (T1005, T1020, T1027), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-0307
- Threat ID
- TL-2026-0307
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-04-01
- Last reviewed
- 2026-04-01
- Attribution
- UNC5221
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government, financial, healthcare, technology, telecommunications, defense, energy, critical-infrastructure
- Target regions
- North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in CVE-2025-53521
Malware and tooling: BRICKSTORM - S9015, BRICKSTORM C2 via TLS/HTTP2/WebSocket/Yamux
CVE-2025-53521 is a critical (CVSS 9.8) unauthenticated remote code execution vulnerability in F5 BIG-IP Access Policy Manager affecting the apmd process. Originally disclosed in October 2025 as a denial-of-service issue, it was reclassified as RCE in March 2026 after evidence of active exploitation by Chinese nation-state actor UNC5221. CISA added it to the KEV catalog on March 27, 2026.
How CVE-2025-53521 works
CVE-2025-53521 is a critical pre-authentication remote code execution vulnerability in the apmd process of F5 BIG-IP Access Policy Manager (APM). The vulnerability is triggered when a BIG-IP APM access policy is configured on a virtual server and the system receives specially crafted malicious traffic, causing a stack-based buffer overflow (CWE-121) that leads to arbitrary code execution with root privileges.
The vulnerability was initially disclosed on October 15, 2025 and classified as a denial-of-service issue with a CVSS score of 8.7. However, in March 2026, F5 reclassified the vulnerability as remote code execution after new intelligence revealed that the flaw was being actively exploited by a sophisticated nation-state threat actor. The updated CVSS scores are 9.8 (v3.1) and 9.3 (v4.0), reflecting the pre-authentication attack vector requiring no user interaction.
The exploitation is linked to UNC5221, a China-nexus threat cluster that maintained persistent access to F5's internal network for at least 12 months prior to discovery in August 2025. During this period, the attackers accessed BIG-IP source code and vulnerability intelligence, which facilitated the development of the exploit. Post-compromise, attackers deployed the BRICKSTORM backdoor — a statically-linked Go ELF executable that uses TLS with HTTP/2 ALPN negotiation, WebSocket upgrade capability, and Yamux multiplexing for concurrent C2 streams over a single socket.
The observed attack chain proceeds as follows: (1) Reconnaissance via queries to /mgmt/shared/identified-devices/config/device-info to enumerate vulnerable systems; (2) Exploitation of the apmd process on internet-exposed APM instances achieving root-level code execution; (3) Persistence through SSH key injection into /root/.ssh/authorized_keys and /home/tmadmin/.ssh/authorized_keys, modification of systemd units, and deployment of in-memory webshells; (4) Defense evasion by modifying sys-eicheck (system integrity checker) and disabling SELinux; (5) Credential harvesting via iControl REST API interception and SSO token theft; (6) Lateral movement using the compromised APM as a pivot point to downstream internal and SaaS systems.
Indicators of compromise include the presence of /run/bigtlog.pipe and /run/bigstart.ltm persistence files, hash mismatches in /usr/bin/umount and /usr/sbin/httpd binaries, webshell modifications to PHP files under /var/sam/www/webtop/renderer/, and HTTP/S traffic containing HTTP 201 response codes with CSS content-type headers used for C2 obfuscation. POST requests to http://localhost:8100/mgmt/tm/util/bash with HTTP 200 responses indicate post-exploitation command execution.
The vulnerability affects BIG-IP APM versions 15.1.0-15.1.10, 16.1.0-16.1.6, 17.1.0-17.1.2, and 17.5.0-17.5.1, as well as BIG-IP systems in Appliance mode. F5 released patches in October 2025 that address the vulnerability. CISA added CVE-2025-53521 to the Known Exploited Vulnerabilities catalog on March 27, 2026, with a mandatory federal agency remediation deadline of March 30, 2026. The Dutch National Cyber Security Center (NCSC-NL) independently confirmed active exploitation on March 30, 2026.
MITRE ATT&CK techniques used in TL-2026-0307
collection
exfiltration
T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal
execution
T1059 Command and Scripting Interpreter; T1106 Native API
privilege-escalation
T1068 Exploitation for Privilege Escalation
command-and-control
T1071 Application Layer Protocol; T1090 Proxy; T1572 Protocol Tunneling; T1573 Encrypted Channel
discovery
T1082 System Information Discovery
persistence
T1098 Account Manipulation; T1505 Server Software Component; T1543 Create or Modify System Process
initial-access
T1190 Exploit Public-Facing Application
impact
T1499 Endpoint Denial of Service
credential-access
T1539 Steal Web Session Cookie; T1552 Unsecured Credentials
lateral-movement
reconnaissance
defense-impairment
Affected products and versions in CVE-2025-53521
- F5 — BIG-IP Access Policy Manager (APM)
Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8 - F5 — BIG-IP Advanced Firewall Manager
Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8 - F5 — BIG-IP Application Security Manager
Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8 - F5 — BIG-IP SSL Orchestrator
Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8 - F5 — BIG-IP (Appliance mode)
Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8
Remediation for CVE-2025-53521
Patches
- F5 BIG-IP APM 17.5.x: Upgrade to 17.5.1.3
- F5 BIG-IP APM 17.1.x: Upgrade to 17.1.3
- F5 BIG-IP APM 16.1.x: Upgrade to 16.1.6.1
- F5 BIG-IP APM 15.1.x: Upgrade to 15.1.10.8
Immediate actions
- Inventory all F5 BIG-IP APM instances and identify vulnerable versions
- Apply patches: upgrade to 17.5.1.3, 17.1.3, 16.1.6.1, or 15.1.10.8
- Hunt for IOCs: check for /run/bigtlog.pipe, /run/bigstart.ltm, hash mismatches in /usr/bin/umount and /usr/sbin/httpd
- Review /var/log/restjavad-audit logs for suspicious localhost iControl REST API access
- Check /root/.ssh/authorized_keys and /home/tmadmin/.ssh/authorized_keys for unauthorized SSH keys
- Block external access to /mgmt/shared/identified-devices/config/device-info endpoint
Workarounds
- If patching is not immediately possible, restrict access to BIG-IP APM virtual servers to trusted networks
- Disable APM access policies on internet-facing virtual servers until patches are applied
- Monitor for anomalous outbound HTTPS connections on non-standard ports (8443, 9443)
Longer-term hardening
- Restrict BIG-IP management interface to trusted internal networks only
- Enable multi-factor authentication for all BIG-IP administrative access
- Forward all BIG-IP logs to external SIEM for continuous monitoring
- Implement network segmentation to limit lateral movement from compromised APM devices
- Deploy EDR with behavioral detection on management networks
- Establish binary integrity monitoring for critical BIG-IP system files
CVEs associated with CVE-2025-53521
Weaknesses (CWE) in CVE-2025-53521
CWE-121
Timeline of CVE-2025-53521
- Estimated earliest date of UNC5221 unauthorized access to F5 internal systems (maintained access for at least 12 months prior to August 2025 discovery)
- F5 discovered unauthorized access on internal systems by nation-state threat actor UNC5221
- U.S. Department of Justice permitted delayed disclosure of the F5 breach
- CISA issued Emergency Directive ED-26-01 regarding F5 BIG-IP vulnerabilities
- F5 released patches for all affected BIG-IP APM branches: 17.5.1.3, 17.1.3, 16.1.6.1, 15.1.10.8
- F5 published security advisory K000156741 classifying CVE-2025-53521 as denial-of-service (CVSS 8.7)
- Resecurity published detailed analysis linking F5 source code leak to BRICKSTORM backdoor campaigns
- CISA/NSA released updated Malware Analysis Report on BRICKSTORM backdoor with IOCs and detection signatures including Rust-based variants
- CISA added CVE-2025-53521 to Known Exploited Vulnerabilities catalog with March 30, 2026 federal remediation deadline
- F5 reclassified CVE-2025-53521 from DoS to RCE based on new information, updating CVSS to 9.8 (v3.1) and 9.3 (v4.0)
- Defused Cyber confirmed acute scanning activity for vulnerable F5 BIG-IP devices targeting /mgmt/shared/identified-devices/config/device-info
- Multiple security vendors (Help Net Security, eSentire, The Hacker News) publicly confirmed active exploitation of CVE-2025-53521
- Dutch National Cyber Security Center (NCSC-NL) independently confirmed active exploitation of CVE-2025-53521
- SOCRadar published detailed analysis of CVE-2025-53521 reclassification from DoS to RCE
- As of 2026-05-29, CVE-2025-53521 (F5 BIG-IP APM RCE, CVSS 9.8) remains actively exploited and a live CISA KEV entry; patches exist (Oct 2025) but 14,000+ instances stayed exposed/unpatched into April 2026. China-nexus UNC5221 continues BRICKSTORM-based intrusions with no takedown, arrest, or successor, so the threat is ACTIVE not merely PATCHED.
Sources cited for CVE-2025-53521
- NVD - CVE-2025-53521
- F5 Security Advisory K000156741
- CISA Known Exploited Vulnerabilities Catalog
- SOCRadar - CVE-2025-53521 Reclassified as RCE
- CISA Adds CVE-2025-53521 to KEV - The Hacker News
- Attackers exploiting RCE in BIG-IP APM - Help Net Security
- Resecurity - F5 BIG-IP Source Code Leak and BRICKSTORM Backdoor
- UK NCSC Advisory - Vulnerability affecting F5 BIG-IP APM
- NHS England Digital - Critical RCE in F5 BIG-IP Under Exploitation
- Qualys ThreatPROTECT - CISA Warns about CVE-2025-53521
- eSentire - F5 BIG-IP APM Flaw Exploited in the Wild
- Hadrian - F5 BIG-IP APM RCE Active Exploitation
- CISA/NSA BRICKSTORM Backdoor Malware Analysis Report
- CyCognito - Emerging Threat CVE-2025-53521
- F5 BIG-IP DoS Flaw Upgraded to Critical RCE - SecurityWeek
Threats related to CVE-2025-53521
- CVE-2025-53521: F5 BIG-IP APM Unauthenticated Remote Code Execution via apmd Process — Active Exploitation by UNC5221 (BRICKSTORM)
- F5 BIG-IP APM Unauthenticated Remote Code Execution via Stack Buffer Overflow (CVE-2025-53521) — CISA KEV Active Exploitation by Chinese Nation-State Actor
- BRICKSTORM Backdoor: UNC5221 PRC-Nexus APT Targeting VMware vSphere Infrastructure
- VerdantBamboo (UNC5221 / WARP PANDA) BRICKSTORM Campaign — MSP Supply-Chain Compromise of Edge Appliances with 18-Month Dwell
- Dell RecoverPoint Hardcoded Credentials RCE + UNC6201 GRIMBOLT Backdoor (CVE-2026-22769)
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Access
Detection coverage for TL-2026-0307
As of 2026-04-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0307 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.