CVE-2020-5902
CVE-2020-5902
In short
A critical vulnerability in F5 BIG-IP's web management interface allows attackers to execute arbitrary code on affected systems without authentication. This flaw affects multiple versions and can lead to complete system compromise.
Technical detail
CVE-2020-5902 is a pre-authentication RCE vulnerability in BIG-IP TMUI affecting versions 11.6.1–15.1.0.3, exploitable via undisclosed pages with a network attack vector. The vulnerability allows unauthenticated remote code execution with CVSS 9.8 severity, resulting in complete system compromise.
Summary generated and translated by AI from the official description.
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · BIG-IPpublic PoCs found — 64
githubgithub.com/jas502n/CVE-2020-5902★ 374githubgithub.com/yassineaboukir/CVE-2020-5902★ 71githubgithub.com/theLSA/f5-bigip-rce-cve-2020-5902★ 62githubgithub.com/aqhmal/CVE-2020-5902-Scanner★ 55githubgithub.com/yasserjanah/CVE-2020-5902★ 43githubgithub.com/dunderhay/CVE-2020-5902★ 36githubgithub.com/f5devcentral/cve-2020-5902-ioc-bigip-checker★ 17githubgithub.com/zhzyker/CVE-2020-5902★ 13githubgithub.com/ar0dd/CVE-2020-5902★ 12githubgithub.com/PushpenderIndia/CVE-2020-5902-Scanner★ 12githubgithub.com/Al1ex/CVE-2020-5902★ 10githubgithub.com/lijiaxing1997/CVE-2020-5902-POC-EXP★ 10githubgithub.com/west9b/F5-BIG-IP-POC★ 10githubgithub.com/dwisiswant0/CVE-2020-5902★ 9githubgithub.com/nsflabs/CVE-2020-5902★ 8githubgithub.com/rwincey/CVE-2020-5902-NSE★ 8githubgithub.com/rockmelodies/CVE-2020-5902-rce-gui★ 8githubgithub.com/sv3nbeast/CVE-2020-5902_RCE★ 8githubgithub.com/GovindPalakkal/EvilRip★ 6githubgithub.com/MrCl0wnLab/checker-CVE-2020-5902★ 5githubgithub.com/corelight/CVE-2020-5902-F5BigIP★ 4githubgithub.com/jiansiting/CVE-2020-5902★ 4githubgithub.com/d4rk007/F5-Big-IP-CVE-2020-5902-mass-exploiter★ 4githubgithub.com/34zY/APT-Backpack★ 3githubgithub.com/r0ttenbeef/cve-2020-5902★ 2githubgithub.com/cybersecurityworks553/scanner-CVE-2020-5902★ 2githubgithub.com/DeepSecurity-Pe/GoF5-CVE-2020-5902★ 2githubgithub.com/qiong-qi/CVE-2020-5902-POC★ 2githubgithub.com/murataydemir/CVE-2020-5902★ 2githubgithub.com/faisalfs10x/F5-BIG-IP-CVE-2020-5902-shodan-scanner★ 2githubgithub.com/z3n70/CVE-2020-5902★ 2githubgithub.com/renanhsilva/checkvulnCVE20205902★ 1githubgithub.com/qlkwej/poc-CVE-2020-5902★ 1githubgithub.com/halencarjunior/f5scan★ 1githubgithub.com/haisenberg/CVE-2020-5902★ 1githubgithub.com/amitlttwo/CVE-2020-5902★ 1githubgithub.com/Shu1L/CVE-2020-5902-fofa-scan★ 1githubgithub.com/JSec1337/RCE-CVE-2020-5902★ 1githubgithub.com/0xAbdullah/CVE-2020-5902★ 1githubgithub.com/jinnywc/CVE-2020-5902★ 1githubgithub.com/Zinkuth/F5-BIG-IP-CVE-2020-5902★ 1githubgithub.com/ajdumanhug/CVE-2020-5902★ 0githubgithub.com/dnerzker/CVE-2020-5902★ 0githubgithub.com/TheCyberViking/CVE-2020-5902-Vuln-Checker★ 0githubgithub.com/0xBlackash/CVE-2020-5902★ 0githubgithub.com/flyopenair/CVE-2020-5902★ 0githubgithub.com/freeFV/CVE-2020-5902-fofa-scan★ 0githubgithub.com/momika233/cve-2020-5902★ 0githubgithub.com/superzerosec/cve-2020-5902★ 0githubgithub.com/ludy-dev/BIG-IP-F5-TMUI-RCE-Vulnerability★ 0githubgithub.com/Any3ite/CVE-2020-5902-F5BIG★ 0githubgithub.com/k3nundrum/CVE-2020-5902★ 0githubgithub.com/inho28/CVE-2020-5902-F5-BIGIP★ 0githubgithub.com/cristiano-corrado/f5_scanner★ 0githubgithub.com/GoodiesHQ/F5-Patch★ 0cve_referencepacketstormsecurity.com/files/158333/BIG-IP-TMUI-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/158366/F5-BIG-IP-TMUI-Directory-Traversal-File-Upload-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/175671/F5-BIG-IP-TMUI-Directory-Traversal-File-Upload-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/158581/F5-Big-IP-13.1.3-Build-0.0.6-Local-File-Inclusion.htmlunverifiedcve_referencepacketstormsecurity.com/files/158414/Checker-CVE-2020-5902.htmlunverifiedexploitdbwww.exploit-db.com/exploits/48711unverifiedexploitdbwww.exploit-db.com/exploits/48643unverifiedcve_referencepacketstormsecurity.com/files/158334/BIG-IP-TMUI-Remote-Code-Execution.htmlunverifiedexploitdbwww.exploit-db.com/exploits/48642unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://packetstormsecurity.com/files/158333/BIG-IP-TMUI-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/158334/BIG-IP-TMUI-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/158366/F5-BIG-IP-TMUI-Directory-Traversal-File-Upload-Code-Execution.htmlhttp://packetstormsecurity.com/files/158414/Checker-CVE-2020-5902.htmlhttp://packetstormsecurity.com/files/158581/F5-Big-IP-13.1.3-Build-0.0.6-Local-File-Inclusion.htmlhttp://packetstormsecurity.com/files/175671/F5-BIG-IP-TMUI-Directory-Traversal-File-Upload-Code-Execution.htmlhttps://badpackets.net/over-3000-f5-big-ip-endpoints-vulnerable-to-cve-2020-5902/https://github.com/Critical-Start/Team-Ares/tree/master/CVE-2020-5902https://support.f5.com/csp/article/K52145254https://swarm.ptsecurity.com/rce-in-f5-big-ip/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5902https://www.criticalstart.com/f5-big-ip-remote-code-execution-exploit/