Executive brief
A vulnerability in F5 BIG-IP networking appliances allows a highly privileged user to escalate their permissions further by modifying configuration objects. BIG-IP systems are widely used for managing enterprise network traffic, security, and application delivery. An exploit could allow an administrator to gain unauthorized control over the system, potentially leading to full compromise of the device and the traffic it manages.
Technical details
A command injection vulnerability (CWE-77) exists in F5 BIG-IP systems within the configuration management interface. An authenticated attacker possessing at least the Resource Administrator role can exploit this flaw by modifying specific configuration objects. This leads to privilege escalation, potentially allowing the attacker to execute arbitrary commands or gain full administrative control over the appliance. The vulnerability affects multiple BIG-IP modules including APM, AFM, and Local Traffic Manager across versions 16.1.x, 17.5.x, and 21.0.0. F5 has released advisory K000160975 to address the issue.
Affected products
- F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Advanced WAF 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
Timeline
- 2026-05-13: advisory: Initial publication of the vulnerability advisory