CVE-2025-53860

A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIPS hardware security module (HSM) information on F5 rSeries systems.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Link Resource
https://my.f5.com/manage/s/article/K000148625 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:f5:f5os-a:*:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-a:1.8.0:*:*:*:*:*:*:*
OR cpe:2.3:h:f5:r10920-df:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:r5920-df:-:*:*:*:*:*:*:*

History

21 Oct 2025, 12:01

Type Values Removed Values Added
First Time F5 r10920-df
F5 r5920-df
F5 f5os-a
F5
References () https://my.f5.com/manage/s/article/K000148625 - () https://my.f5.com/manage/s/article/K000148625 - Vendor Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:h:f5:r10920-df:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-a:*:*:*:*:*:*:*:*
cpe:2.3:h:f5:r5920-df:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-a:1.8.0:*:*:*:*:*:*:*

15 Oct 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-15 16:15

Updated : 2025-10-21 12:01


NVD link : CVE-2025-53860

Mitre link : CVE-2025-53860

CVE.ORG link : CVE-2025-53860


JSON object : View

Products Affected

f5

  • r5920-df
  • r10920-df
  • f5os-a
CWE
CWE-214

Invocation of Process Using Visible Sensitive Information

NVD-CWE-noinfo