Executive brief
F5 BIG-IP and BIG-IQ networking devices contain a security flaw where certain administrative commands do not have proper permission restrictions. This allows an authorized user with low-level access to view sensitive information about the surrounding network infrastructure that they should not be able to see. This could be used by an attacker to map out a corporate network for further attacks.
Technical details
An incorrect permission assignment vulnerability (CWE-732) exists in the TMOS Shell (tmsh) and iControl REST interface of F5 BIG-IP and BIG-IQ. Specifically, the 'arp' and 'ndp' commands in tmsh, along with related iControl REST endpoints, do not properly enforce access controls. An authenticated attacker with network access to these interfaces can execute these commands to view ARP and NDP tables, exposing information about adjacent network devices. The vulnerability affects BIG-IP versions 17.x and 16.x, as well as BIG-IQ. F5 has provided mitigation guidance and software updates to address the issue.
Affected products
- F5 BIG-IP 17.1.0 - 17.1.3.1, 17.5.0 - 17.5.1.4, 16.1.0 - 16.1.6
- F5 BIG-IQ All versions
Timeline
- 2026-05-13: advisory: Initial publication by F5 Networks