Home / os / winme

F5 BIG-IP iControl Remote Code Execution

Posted on 12 May 2022

This Metasploit module exploits an authentication bypass vulnerability in the F5 BIG-IP iControl REST service to gain access to the admin account, which is capable of executing commands through the /mgmt/tm/util/bash endpoint. Successful exploitation results in remote code execution as the root user.

 

TOP