logo

F5 TMUI RCE Vulnerability CVE-2020-5902 Explained

ID: 4e4ab823-93fa-58af-b3c8-709f2fccf00b

STIX ID: report--4e4ab823-93fa-58af-b3c8-709f2fccf00b

Feed Name: NCC Research

Threat Score
90/100

Date Published: 2026-05-15

Date Updated: 2026-08-01

...
...

This NCC Group RIFT report documents active exploitation of CVE-2020-5902 (F5 BIG‑IP TMUI RCE), detailing rapid weaponization and widespread scanning/exploitation beginning in early July 2020. The report includes timelines, multiple staged payloads, web shells, cryptominer deployments, mitigation bypasses that re-exposed thousands of devices, IoCs (file hashes, filenames, IPs, and payload snippets), and operational guidance urging patching, forensic examination of potentially compromised devices, and SIEM/syslog configuration for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.