Executive brief
F5 BIG-IP and BIG-IQ networking devices contain a security flaw in their diagnostic tools and management interfaces. An authorized user with low-level access could exploit this to view sensitive network status information about other systems they should not be able to see. This could lead to unauthorized reconnaissance of the internal network environment.
Technical details
An incorrect permission assignment vulnerability (CWE-732) exists in the TMOS Shell (tmsh) network diagnostics commands and the iControl REST interface. The flaw allows an authenticated attacker with low privileges to execute diagnostic utilities that reveal the network status of destination systems. On BIG-IP, the vulnerability affects both the command-line shell and the REST API, while on BIG-IQ it affects the shell commands. Attackers can leverage this to perform internal network discovery. F5 has released updates for affected BIG-IP versions (16.x, 17.x, and 21.x).
Affected products
- F5 BIG-IP 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IQ All versions (EoTS excluded)
Timeline
- 2026-05-13: advisory: Initial publication of the advisory by F5