F5 BIG-IP and BIG-IQ Configuration Utility Authenticated Remote Code Execution Vulnerability

Vulnerability

A vulnerability allowing authenticated remote code execution exists in the BIG-IP and BIG-IQ Configuration utilities. This issue arises through undisclosed vectors, enabling an authenticated attacker with network access to the Configuration utility via the BIG-IP management port or self IP addresses to execute arbitrary system commands, manipulate files, or disrupt services. Notably, this vulnerability does not expose data plane operations, focusing solely on control plane functions.

Impact

Exploitation of this vulnerability could allow an authenticated attacker to execute arbitrary commands on the system, potentially leading to unauthorized access or manipulation of files and services.

Remediation

Users can upgrade to versions 21.0.0, 17.5.1.4, 17.1.3.1, or 8.4.1 to address this vulnerability. For more information on managing F5 product hotfixes, refer to the F5 knowledge article K13123 for BIG-IP and K15106 for BIG-IQ.

Added: May 13, 2026, 8:03 PM
Updated: May 13, 2026, 8:03 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
2.9
remediation
7.9
relevance
8.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.