logo

CVE-2020-5902 Analysis, F5 BIG-IP RCE Vulnerability

ID: d70a79c5-d5f7-5b50-b8b2-806965608ec0

STIX ID: report--d70a79c5-d5f7-5b50-b8b2-806965608ec0

Feed Name: CertiK Blog

Threat Score
90/100

Date Published: 2020-07-07

Date Updated: 2026-06-11

...
...

This report analyzes CVE-2020-5902, a critical remote code execution vulnerability in F5 BIG-IP TMUI (CVSS 10). It details affected versions, PoC curl commands for arbitrary file read and tmsh command execution, step-by-step reproduction, the root cause (inconsistent URL parsing between Apache and Tomcat enabling "/..;/" bypass), and a temporary httpd configuration mitigation; the report also notes widespread exploitation activity following public disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.