Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

F5

Vulnerabilities in F5 BIG-IP's iControl REST and TMUI management interfaces — application-delivery controllers whose compromise typically hands attackers control of the load-balanced traffic behind them.

8 CVEs1 articlesRSS
CVEs
CVE-2026-42533
[ HIGH ]CVSS 8.1EPSS 3.5%patched

nginx map directive regex-capture heap buffer overflow in worker

A heap buffer overflow in the nginx worker process when a map directive's string expression references its regex capture variables before the output variable. Reachable via crafted HTTP; DoS by worker restart, code execution possible only where ASLR is disabled or bypassable.

F5 / nginx (open source), NGINX Plus
CVE-2025-53521
[ CRITICAL ]CVSS 9.8EPSS 2.2%kev

F5 BIG-IP Stack-Based Buffer Overflow Vulnerability

F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.

F5 / BIG-IP
CVE-2023-46747
[ CRITICAL ]CVSS 9.8EPSS 96.5%kev

F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.

F5 / BIG-IP Configuration Utility
CVE-2023-46748
[ HIGH ]CVSS 8.8EPSS 4.5%kev

F5 BIG-IP Configuration Utility SQL Injection Vulnerability

F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747.

F5 / BIG-IP Configuration Utility
CVE-2022-1388
[ CRITICAL ]CVSS 9.8EPSS 100.0%kev

F5 BIG-IP iControl REST Authentication Bypass

An authentication-bypass vulnerability in the F5 BIG-IP iControl REST API allows an unauthenticated attacker with network access to the management interface or self-IP addresses to execute arbitrary system commands, create or delete files, or disable services.

F5 / BIG-IP
CVE-2021-22991
[ CRITICAL ]CVSS 9.8EPSS 61.1%kev

F5 BIG-IP Traffic Management Microkernel Buffer Overflow

The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.

F5 / BIG-IP Traffic Management Microkernel
CVE-2020-5902
[ CRITICAL ]CVSS 9.8EPSS 100.0%kev

F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability

F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.

F5 / BIG-IP
CVE-2021-22986
[ CRITICAL ]CVSS 9.8EPSS 99.9%kev

F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.

F5 / BIG-IP and BIG-IQ Centralized Management
Articles