Executive brief
A security vulnerability has been identified in F5 BIG-IP devices, which are widely used to manage and secure enterprise network traffic. An authorized administrator could exploit this flaw to run unauthorized commands with elevated system privileges. In certain high-security configurations, this could allow an attacker to bypass critical security boundaries and gain deeper control over the appliance.
Technical details
A vulnerability classified as 'Execution with Unnecessary Privileges' (CWE-250) exists in F5 BIG-IP scripted monitors. An authenticated attacker assigned the Resource Administrator or Administrator role can exploit this to execute arbitrary system commands with higher privileges than intended. In appliance mode deployments, this flaw facilitates a security boundary crossing. The attack vector is network-based, requiring high privileges but no user interaction. Affected versions include the 16.1.x and 17.5.x branches, as well as version 21.0.0. F5 has released advisory K000161040 to address the issue.
Affected products
- F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Advanced WAF 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP DNS 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
Timeline
- 2026-05-13: advisory: Initial publication of the vulnerability advisory.