logo

Critical F5 Central Manager Vulnerabilities Allow Enable Full Device Takeover

ID: 2575f6cb-88df-5d00-89f8-144529613956

STIX ID: report--2575f6cb-88df-5d00-89f8-144529613956

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-05-09

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Two remotely exploitable SQL/OData injection vulnerabilities (CVE-2024-21793 and CVE-2024-26026; CVSS 7.5) in F5 BIG‑IP Next Central Manager (affecting 20.0.1–20.1.0) can allow unauthenticated attackers to execute SQL, gain full administrative control, and — via an SSRF invoking an undocumented API — create hidden administrator accounts that persist across managed assets; other issues enable brute‑force attacks and admin password resets. These flaws are resolved in version 20.2.0; no active exploitation has been observed, and users are advised to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.