Medium severity6.1NVD Advisory· Published Oct 15, 2025· Updated Jun 17, 2026
CVE-2025-61933
CVE-2025-61933
Description
A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker to run JavaScript in the context of the targeted logged-out user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected products
2Patches
Vulnerability mechanics
References
1- my.f5.com/manage/s/article/K000156596nvdVendor Advisory
News mentions
0No linked articles in our index yet.