Junglewise Threat Intelligence

CVE-2026-42937: F5 BIG-IP and BIG-IQ incorrect permission assignment in tmsh and iControl REST

CVE-2026-42937 · Severity: medium · CVSS 6.5 · Published 2026-05-13

Executive brief

F5 BIG-IP and BIG-IQ networking devices contain a security flaw where certain administrative commands do not have proper permission restrictions. This allows an authorized user with low-level access to view sensitive information about the surrounding network infrastructure that they should not be able to see. This could be used by an attacker to map out a corporate network for further attacks.

Technical details

An incorrect permission assignment vulnerability (CWE-732) exists in the TMOS Shell (tmsh) and iControl REST interface of F5 BIG-IP and BIG-IQ. Specifically, the 'arp' and 'ndp' commands in tmsh, along with related iControl REST endpoints, do not properly enforce access controls. An authenticated attacker with network access to these interfaces can execute these commands to view ARP and NDP tables, exposing information about adjacent network devices. The vulnerability affects BIG-IP versions 17.x and 16.x, as well as BIG-IQ. F5 has provided mitigation guidance and software updates to address the issue.

Affected products

  • F5 BIG-IP 17.1.0 - 17.1.3.1, 17.5.0 - 17.5.1.4, 16.1.0 - 16.1.6
  • F5 BIG-IQ All versions

Timeline

  • 2026-05-13: advisory: Initial publication by F5 Networks

References

Related threats