Executive brief
F5 BIG-IP and BIG-IQ devices, which are used for network traffic management and security, contain a vulnerability in their management interface. An attacker with low-level login credentials could take complete control of the device remotely. This could lead to the interception of network traffic, data theft, or a total disruption of network services.
Technical details
An authenticated remote code execution (RCE) vulnerability exists in the BIG-IP and BIG-IQ Configuration utility (management interface). The vulnerability is rooted in the deserialization of untrusted data (CWE-502). An attacker with network access to the management port and valid low-privileged credentials can exploit this flaw to execute arbitrary commands on the underlying operating system. The vulnerability affects multiple BIG-IP modules including APM, AFM, and ASM. F5 has released a vendor advisory (K000156761) detailing mitigations and affected versions.
Affected products
- F5 BIG-IP 16.1.0 - 16.1.6, 17.5.0 - 17.5.1
- F5 BIG-IQ Centralized Management 8.4.0
Timeline
- 2026-05-13: advisory: Initial publication of the vulnerability advisory