F5 iControl REST and TMOS Shell Vulnerability Allowing Arbitrary Command Execution

Vulnerability

A vulnerability exists in iControl REST and the TMOS Shell (tmsh) that allows a highly privileged, authenticated attacker with at least the Manager role to create configuration objects enabling the execution of arbitrary commands. This issue is present in BIG-IP versions 21.0.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3, as well as in BIG-IQ Centralized Management. The vulnerability arises from a least privilege violation, allowing unauthorized command execution and file manipulation.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of system commands and manipulation of files on the affected system.

Remediation

Users can upgrade to BIG-IP versions 17.5.1.6, 17.1.3.2, or 21.0.0.2, depending on their current version. For BIG-IQ Centralized Management, no update is currently available, and users are advised to upgrade to a version with the fix. Until a fixed version can be installed, access to iControl REST and the BIG-IP command line through SSH can be restricted to trusted networks or devices.

Added: May 13, 2026, 6:21 PM
Updated: May 13, 2026, 6:21 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
7.5
exploitability
3.6
remediation
7.9
relevance
8.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.