logo

The Confusing History of F5 BIG-IP RCE Vulnerabilities

ID: b1dcea48-2bdd-5f1d-917d-352bf50ab327

STIX ID: report--b1dcea48-2bdd-5f1d-917d-352bf50ab327

Feed Name: GreyNoise Labs

Threat Score
75/100

Date Published: 2024-01-19

Date Updated: 2026-04-27

Author: Ron Bowes

...
...

This report analyzes several F5 BIG-IP vulnerabilities and in-the-wild exploitation attempts — including SSRF-based auth bypass leading to RCE (CVE-2021-22986), header-smuggling auth bypass (CVE-2022-1388), post-auth command injection (CVE-2021-23015), and rpmspec injection (CVE-2022-41800) — providing PoCs, observed HTTP request patterns, and detection/tagging recommendations based on GreyNoise sensor captures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.