CVE-2020-5902 Analysis, F5 BIG-IP RCE Vulnerability
ID: d70a79c5-d5f7-5b50-b8b2-806965608ec0
STIX ID: report--d70a79c5-d5f7-5b50-b8b2-806965608ec0
Feed Name: CertiK Blog
Threat Score
This report analyzes CVE-2020-5902, a critical remote code execution vulnerability in F5 BIG-IP TMUI (CVSS 10). It details affected versions, PoC curl commands for arbitrary file read and tmsh command execution, step-by-step reproduction, the root cause (inconsistent URL parsing between Apache and Tomcat enabling "/..;/" bypass), and a temporary httpd configuration mitigation; the report also notes widespread exploitation activity following public disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
