F5 TMUI RCE Vulnerability CVE-2020-5902 Explained
ID: 4e4ab823-93fa-58af-b3c8-709f2fccf00b
STIX ID: report--4e4ab823-93fa-58af-b3c8-709f2fccf00b
Feed Name: NCC Research
This NCC Group RIFT report documents active exploitation of CVE-2020-5902 (F5 BIG‑IP TMUI RCE), detailing rapid weaponization and widespread scanning/exploitation beginning in early July 2020. The report includes timelines, multiple staged payloads, web shells, cryptominer deployments, mitigation bypasses that re-exposed thousands of devices, IoCs (file hashes, filenames, IPs, and payload snippets), and operational guidance urging patching, forensic examination of potentially compromised devices, and SIEM/syslog configuration for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
