F5 iControl REST and TMOS Shell Incorrect Permission Assignment Vulnerability Allowing Sensitive Information Disclosure

Vulnerability

A vulnerability exists in iControl REST and the TMOS shell (tmsh) due to incorrect permission assignments in an undisclosed command. This vulnerability may enable an authenticated attacker to access sensitive information. The issue is limited to the control plane and does not involve data plane exposure.

Impact

Exploitation of this vulnerability could allow an authenticated attacker to view sensitive information through iControl REST or tmsh commands.

Remediation

Users can block access to the iControl REST interface through self IP addresses by changing the Port Lockdown setting to 'Allow None' for each self IP address. If necessary, custom options can be used to disallow access to iControl REST while opening other ports. For management interfaces, access should be restricted to trusted users and devices over secure networks. Similar measures can be applied to SSH access through self IP addresses or the management interface.

Added: May 13, 2026, 6:15 PM
Updated: May 13, 2026, 6:15 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
3.5
remediation
0.0
relevance
8.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.