CVE-2025-53521: F5 BIG-IP APM Unauthenticated Remote Code Execution via Stack-based Buffer Overflow

CVE-2025-53521 (TL-2026-0307) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-04-01. It is attributed to UNC5221 (China) with high confidence, affects F5 BIG-IP Access Policy Manager (APM), references 1 CVE (CVE-2025-53521), maps to 24 MITRE ATT&CK techniques (T1005, T1020, T1027), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-0307

Threat ID
TL-2026-0307
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-04-01
Last reviewed
2026-04-01
Attribution
UNC5221
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government, financial, healthcare, technology, telecommunications, defense, energy, critical-infrastructure
Target regions
North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
20

Malware and tooling in CVE-2025-53521

Malware and tooling: BRICKSTORM - S9015, BRICKSTORM C2 via TLS/HTTP2/WebSocket/Yamux

CVE-2025-53521 is a critical (CVSS 9.8) unauthenticated remote code execution vulnerability in F5 BIG-IP Access Policy Manager affecting the apmd process. Originally disclosed in October 2025 as a denial-of-service issue, it was reclassified as RCE in March 2026 after evidence of active exploitation by Chinese nation-state actor UNC5221. CISA added it to the KEV catalog on March 27, 2026.

How CVE-2025-53521 works

CVE-2025-53521 is a critical pre-authentication remote code execution vulnerability in the apmd process of F5 BIG-IP Access Policy Manager (APM). The vulnerability is triggered when a BIG-IP APM access policy is configured on a virtual server and the system receives specially crafted malicious traffic, causing a stack-based buffer overflow (CWE-121) that leads to arbitrary code execution with root privileges.

The vulnerability was initially disclosed on October 15, 2025 and classified as a denial-of-service issue with a CVSS score of 8.7. However, in March 2026, F5 reclassified the vulnerability as remote code execution after new intelligence revealed that the flaw was being actively exploited by a sophisticated nation-state threat actor. The updated CVSS scores are 9.8 (v3.1) and 9.3 (v4.0), reflecting the pre-authentication attack vector requiring no user interaction.

The exploitation is linked to UNC5221, a China-nexus threat cluster that maintained persistent access to F5's internal network for at least 12 months prior to discovery in August 2025. During this period, the attackers accessed BIG-IP source code and vulnerability intelligence, which facilitated the development of the exploit. Post-compromise, attackers deployed the BRICKSTORM backdoor — a statically-linked Go ELF executable that uses TLS with HTTP/2 ALPN negotiation, WebSocket upgrade capability, and Yamux multiplexing for concurrent C2 streams over a single socket.

The observed attack chain proceeds as follows: (1) Reconnaissance via queries to /mgmt/shared/identified-devices/config/device-info to enumerate vulnerable systems; (2) Exploitation of the apmd process on internet-exposed APM instances achieving root-level code execution; (3) Persistence through SSH key injection into /root/.ssh/authorized_keys and /home/tmadmin/.ssh/authorized_keys, modification of systemd units, and deployment of in-memory webshells; (4) Defense evasion by modifying sys-eicheck (system integrity checker) and disabling SELinux; (5) Credential harvesting via iControl REST API interception and SSO token theft; (6) Lateral movement using the compromised APM as a pivot point to downstream internal and SaaS systems.

Indicators of compromise include the presence of /run/bigtlog.pipe and /run/bigstart.ltm persistence files, hash mismatches in /usr/bin/umount and /usr/sbin/httpd binaries, webshell modifications to PHP files under /var/sam/www/webtop/renderer/, and HTTP/S traffic containing HTTP 201 response codes with CSS content-type headers used for C2 obfuscation. POST requests to http://localhost:8100/mgmt/tm/util/bash with HTTP 200 responses indicate post-exploitation command execution.

The vulnerability affects BIG-IP APM versions 15.1.0-15.1.10, 16.1.0-16.1.6, 17.1.0-17.1.2, and 17.5.0-17.5.1, as well as BIG-IP systems in Appliance mode. F5 released patches in October 2025 that address the vulnerability. CISA added CVE-2025-53521 to the Known Exploited Vulnerabilities catalog on March 27, 2026, with a mandatory federal agency remediation deadline of March 30, 2026. The Dutch National Cyber Security Center (NCSC-NL) independently confirmed active exploitation on March 30, 2026.

MITRE ATT&CK techniques used in TL-2026-0307

collection

T1005 Data from Local System

exfiltration

T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal

execution

T1059 Command and Scripting Interpreter; T1106 Native API

privilege-escalation

T1068 Exploitation for Privilege Escalation

command-and-control

T1071 Application Layer Protocol; T1090 Proxy; T1572 Protocol Tunneling; T1573 Encrypted Channel

discovery

T1082 System Information Discovery

persistence

T1098 Account Manipulation; T1505 Server Software Component; T1543 Create or Modify System Process

initial-access

T1190 Exploit Public-Facing Application

impact

T1499 Endpoint Denial of Service

credential-access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials

lateral-movement

T1570 Lateral Tool Transfer

reconnaissance

T1595 Active Scanning

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in CVE-2025-53521

  • F5 — BIG-IP Access Policy Manager (APM)
    Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
    Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8
  • F5 — BIG-IP Advanced Firewall Manager
    Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
    Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8
  • F5 — BIG-IP Application Security Manager
    Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
    Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8
  • F5 — BIG-IP SSL Orchestrator
    Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
    Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8
  • F5 — BIG-IP (Appliance mode)
    Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
    Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8

Remediation for CVE-2025-53521

Patches

  • F5 BIG-IP APM 17.5.x: Upgrade to 17.5.1.3
  • F5 BIG-IP APM 17.1.x: Upgrade to 17.1.3
  • F5 BIG-IP APM 16.1.x: Upgrade to 16.1.6.1
  • F5 BIG-IP APM 15.1.x: Upgrade to 15.1.10.8

Immediate actions

  • Inventory all F5 BIG-IP APM instances and identify vulnerable versions
  • Apply patches: upgrade to 17.5.1.3, 17.1.3, 16.1.6.1, or 15.1.10.8
  • Hunt for IOCs: check for /run/bigtlog.pipe, /run/bigstart.ltm, hash mismatches in /usr/bin/umount and /usr/sbin/httpd
  • Review /var/log/restjavad-audit logs for suspicious localhost iControl REST API access
  • Check /root/.ssh/authorized_keys and /home/tmadmin/.ssh/authorized_keys for unauthorized SSH keys
  • Block external access to /mgmt/shared/identified-devices/config/device-info endpoint

Workarounds

  • If patching is not immediately possible, restrict access to BIG-IP APM virtual servers to trusted networks
  • Disable APM access policies on internet-facing virtual servers until patches are applied
  • Monitor for anomalous outbound HTTPS connections on non-standard ports (8443, 9443)

Longer-term hardening

  • Restrict BIG-IP management interface to trusted internal networks only
  • Enable multi-factor authentication for all BIG-IP administrative access
  • Forward all BIG-IP logs to external SIEM for continuous monitoring
  • Implement network segmentation to limit lateral movement from compromised APM devices
  • Deploy EDR with behavioral detection on management networks
  • Establish binary integrity monitoring for critical BIG-IP system files

CVEs associated with CVE-2025-53521

CVE-2025-53521

Weaknesses (CWE) in CVE-2025-53521

CWE-121

Timeline of CVE-2025-53521

  • Estimated earliest date of UNC5221 unauthorized access to F5 internal systems (maintained access for at least 12 months prior to August 2025 discovery)
  • F5 discovered unauthorized access on internal systems by nation-state threat actor UNC5221
  • U.S. Department of Justice permitted delayed disclosure of the F5 breach
  • CISA issued Emergency Directive ED-26-01 regarding F5 BIG-IP vulnerabilities
  • F5 released patches for all affected BIG-IP APM branches: 17.5.1.3, 17.1.3, 16.1.6.1, 15.1.10.8
  • F5 published security advisory K000156741 classifying CVE-2025-53521 as denial-of-service (CVSS 8.7)
  • Resecurity published detailed analysis linking F5 source code leak to BRICKSTORM backdoor campaigns
  • CISA/NSA released updated Malware Analysis Report on BRICKSTORM backdoor with IOCs and detection signatures including Rust-based variants
  • CISA added CVE-2025-53521 to Known Exploited Vulnerabilities catalog with March 30, 2026 federal remediation deadline
  • F5 reclassified CVE-2025-53521 from DoS to RCE based on new information, updating CVSS to 9.8 (v3.1) and 9.3 (v4.0)
  • Defused Cyber confirmed acute scanning activity for vulnerable F5 BIG-IP devices targeting /mgmt/shared/identified-devices/config/device-info
  • Multiple security vendors (Help Net Security, eSentire, The Hacker News) publicly confirmed active exploitation of CVE-2025-53521
  • Dutch National Cyber Security Center (NCSC-NL) independently confirmed active exploitation of CVE-2025-53521
  • SOCRadar published detailed analysis of CVE-2025-53521 reclassification from DoS to RCE
  • As of 2026-05-29, CVE-2025-53521 (F5 BIG-IP APM RCE, CVSS 9.8) remains actively exploited and a live CISA KEV entry; patches exist (Oct 2025) but 14,000+ instances stayed exposed/unpatched into April 2026. China-nexus UNC5221 continues BRICKSTORM-based intrusions with no takedown, arrest, or successor, so the threat is ACTIVE not merely PATCHED.

Sources cited for CVE-2025-53521

Threats related to CVE-2025-53521

Detection coverage for TL-2026-0307

As of 2026-04-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0307 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats