logo

F5 BIG-IP Unauthenticated RCE via HTTP Request Smuggling

ID: 617c5c3d-95a3-5be6-b5ef-e618f4aec007

STIX ID: report--617c5c3d-95a3-5be6-b5ef-e618f4aec007

Feed Name: Kudelski Security

Threat Score
75/100

Date Published: 2023-10-27

Date Updated: 2026-07-22

...
...

**Executive summary:** Researchers disclosed CVE-2023-46747, a request-smuggling vulnerability in F5 BIG‑IP TMUI (affecting Apache/Tomcat components) that can allow authentication bypass and root remote code execution when the administrative TMUI interface is exposed to untrusted networks; vendors have released hotfixes and recommend restricting TMUI exposure while detection plugins are developed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.