Skip to content

F5 BIG-IP 安全建議公告 – 2026 年 3 月

危急:CVE-2025-53521 已升級為 RCE (CVSS 9.8) – 偵測到活躍攻擊

F5 已確認先前披露的 DoS 漏洞現已演變為 遠端程式碼執行 (RCE) 威脅。所有使用 BIG-IP Access Policy Manager (APM) 的實例必須立即進行修補。

修復建議對照表

受影響版本必備修補版本
17.5.x17.5.1.3 或更高版本
17.1.x17.1.3 或更高版本
16.1.x16.1.6.1 或更高版本
15.1.x15.1.10.8 或更高版本
CISA KEV 狀態: 此漏洞已於 2026 年 3 月 27 日加入已知被利用漏洞目錄。強烈建議聯邦機構與企業立即斷開或修補管理介面。

 

資產識別查詢語句 (runZero)

定位可能受到影響的軟體模組:

vendor:=F5 AND product:=”BIG-IP Access Policy Manager”

定位網路中所有基於 F5 作業系統的設備:

os:=”F5%”

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×