CVE-2025-24320
HIGHDescription
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. This vulnerability is due to an incomplete fix for CVE-2024-31156 https://my.f5.com/manage/s/article/K000138636 . Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Is your site exposed to CVE-2025-24320?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| f5 | big-ip_access_policy_manager |
| f5 | big-ip_advanced_firewall_manager |
| f5 | big-ip_advanced_web_application_firewall |
| f5 | big-ip_analytics |
| f5 | big-ip_application_acceleration_manager |
| f5 | big-ip_application_security_manager |
| f5 | big-ip_application_visibility_and_reporting |
| f5 | big-ip_automation_toolchain |
| f5 | big-ip_carrier-grade_nat |
| f5 | big-ip_container_ingress_services |
| f5 | big-ip_ddos_hybrid_defender |
| f5 | big-ip_domain_name_system |
| f5 | big-ip_edge_gateway |
| f5 | big-ip_fraud_protection_service |
| f5 | big-ip_global_traffic_manager |
| f5 | big-ip_link_controller |
| f5 | big-ip_local_traffic_manager |
| f5 | big-ip_policy_enforcement_manager |
| f5 | big-ip_ssl_orchestrator |
| f5 | big-ip_webaccelerator |
| f5 | big-ip_websafe |
| f5 | big-ip_access_policy_manager |
| f5 | big-ip_advanced_firewall_manager |
| f5 | big-ip_advanced_web_application_firewall |
| f5 | big-ip_analytics |
| f5 | big-ip_application_acceleration_manager |
| f5 | big-ip_application_security_manager |
| f5 | big-ip_application_visibility_and_reporting |
| f5 | big-ip_automation_toolchain |
| f5 | big-ip_carrier-grade_nat |
| f5 | big-ip_container_ingress_services |
| f5 | big-ip_ddos_hybrid_defender |
| f5 | big-ip_domain_name_system |
| f5 | big-ip_edge_gateway |
| f5 | big-ip_fraud_protection_service |
| f5 | big-ip_global_traffic_manager |
| f5 | big-ip_link_controller |
| f5 | big-ip_local_traffic_manager |
| f5 | big-ip_policy_enforcement_manager |
| f5 | big-ip_ssl_orchestrator |
| f5 | big-ip_webaccelerator |
| f5 | big-ip_websafe |
| f5 | big-ip_access_policy_manager |
| f5 | big-ip_advanced_firewall_manager |
| f5 | big-ip_advanced_web_application_firewall |
| f5 | big-ip_analytics |
| f5 | big-ip_application_acceleration_manager |
| f5 | big-ip_application_security_manager |
| f5 | big-ip_application_visibility_and_reporting |
| f5 | big-ip_automation_toolchain |
| f5 | big-ip_carrier-grade_nat |
| f5 | big-ip_container_ingress_services |
| f5 | big-ip_ddos_hybrid_defender |
| f5 | big-ip_domain_name_system |
| f5 | big-ip_edge_gateway |
| f5 | big-ip_fraud_protection_service |
| f5 | big-ip_global_traffic_manager |
| f5 | big-ip_link_controller |
| f5 | big-ip_local_traffic_manager |
| f5 | big-ip_policy_enforcement_manager |
| f5 | big-ip_ssl_orchestrator |
| f5 | big-ip_webaccelerator |
| f5 | big-ip_websafe |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-24320? +
How severe is CVE-2025-24320? +
What products are affected by CVE-2025-24320? +
How do I check if I'm vulnerable to CVE-2025-24320? +
Related Vulnerabilities
WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows …
Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present in the '/blog' endpoint because user …
Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execute JavaScript code in the victim's …
Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers …
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin dashboard's Autodiscover …
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the mailcow web interface …