F5 iControl REST and BIG-IP TMOS Shell Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the iControl REST interface and the BIG-IP TMOS Shell (tmsh) save command. This vulnerability may allow an authenticated attacker to execute arbitrary system commands. Note that software versions that have reached End of Technical Support (EoTS) are not evaluated.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of system commands, potentially allowing for further exploitation of the system or application.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.2
remediation
0.0
relevance
0.0
threat
1.3
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.