OS Command Injection in F5 Networks products - CVE-2020-5902
Published: July 1, 2020 / Updated: November 2, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in undisclosed pages in the Traffic Management User Interface (TMUI), also referred to as the Configuration utility. A remote unauthenticated attacker can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
BIG-IP AAM
BIG-IP Link Controller
BIG-IP AFM
BIG-IP LTM
BIG-IP Analytics
BIG-IP APM
BIG-IP ASM
BIG-IP FPS
BIG-IP GTM
BIG-IP PEM
BIG-IP
How to mitigate CVE-2020-5902
BIG-IP AAM - addressed in versions 11.6.5.2, 12.1.5.2, 13.1.3.4, 14.1.2.6, 15.1.0.4
BIG-IP AFM - addressed in versions 11.6.5.2, 12.1.5.2, 13.1.3.4, 14.1.2.6, 15.1.0.4
BIG-IP LTM - addressed in versions 11.6.5.2, 12.1.5.2, 13.1.3.4, 14.1.2.6, 15.1.0.4
BIG-IP Analytics - addressed in versions 11.6.5.2, 12.1.5.2, 13.1.3.4, 14.1.2.6, 15.1.0.4
BIG-IP APM - addressed in versions 11.6.5.2, 12.1.5.2, 13.1.3.4, 14.1.2.6, 15.1.0.4
BIG-IP ASM - addressed in versions 11.6.5.2, 12.1.5.2, 13.1.3.4, 14.1.2.6, 15.1.0.4
BIG-IP FPS - addressed in versions 11.6.5.2, 12.1.5.2, 13.1.3.4, 14.1.2.6, 15.1.0.4
BIG-IP GTM - addressed in versions 11.6.5.2, 12.1.5.2, 13.1.3.4, 14.1.2.6, 15.1.0.4
BIG-IP Link Controller - addressed in versions 11.6.5.2, 12.1.5.2, 13.1.3.4, 14.1.2.6, 15.1.0.4
BIG-IP PEM - addressed in versions 11.6.5.2, 12.1.5.2, 13.1.3.4, 14.1.2.6, 15.1.0.4
BIG-IP - addressed in versions 11.6.5.2, 12.1.5.2, 13.1.3.4, 14.1.2.6, 15.1.0.4
Links to Public Exploits and PoC-codes
- Exploit #9402 - F5 BIG-IP TMUI Directory Traversal and File Upload RCE (November 2, 2023)
- Exploit #8801 - CVE-2020-5902 (In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulne (February 7, 2023)
- Exploit #8664 - CVE-2020-5902-Scanner () (December 14, 2022)
- Exploit #8122 - CVE-2020-5902 (BIGIP CVE-2020-5902 Exploit POC and automation scanning vulnerability) (July 7, 2022)
- Exploit #7907 - F5-BIG-IP-POC (CVE-2020-5902 CVE-2021-22986 CVE-2022-1388 POC集合) (May 29, 2022)
- Exploit #5697 - BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6.5.1 - Traffic Management User Interface 'TMUI' Remote Code Execution (June 17, 2021)
- Exploit #5692 - F5 Big-IP 13.1.3 Build 0.0.6 - Local File Inclusion (June 17, 2021)
- Exploit #5292 - CVE-2020-5902 (Auto exploit RCE CVE-2020-5902 ) (April 13, 2021)
- Exploit #5281 - CVE-2020-5902-fofa-scan () (April 12, 2021)
- Exploit #5202 - CVE-2020-5902 () (March 7, 2021)
- Exploit #5135 - F5-BIG-IP-CVE-2020-5902-shodan-scanner (simple bash script of F5 BIG-IP TMUI Vulnerability CVE-2020-5902 checker) (February 9, 2021)
- Exploit #5118 - F5-BIG-IP-CVE-2020-5902-checker (simple bash script of F5 BIG-IP CVE-2020-5902 checker) (February 4, 2021)
- Exploit #4791 - CVE-2020-5902-Scanner (Automated F5 Big IP Remote Code Execution (CVE-2020-5902) Scanner Written In Python 3) (November 4, 2020)
- Exploit #4765 - CVE-2020-5903 (CVE-2020-5902) (October 28, 2020)
- Exploit #4654 - CVE-2020-5902-F5BigIP (Clone with backwards compatibility with bro-pkg.meta added) (September 25, 2020)
- Exploit #4588 - BIG-IP-F5-TMUI-RCE-Vulnerability ((CVE-2020-5902) BIG IP F5 TMUI RCE Vulnerability RCE PoC/ Test Script ) (September 11, 2020)
- Exploit #4528 - CVE-2020-5902 ([CVE-2020-5902] F5 BIG-IP Remote Code Execution (RCE)) (September 1, 2020)
- Exploit #4517 - cve-2020-5902 () (August 21, 2020)
- Exploit #3926 - CVE-2020-5902-Scanner (Automated F5 Big IP Remote Code Execution (CVE-2020-5902) Scanner Written In Python 3) (August 10, 2020)
- Exploit #3621 - CVE-2020-5902-F5BigIP (A network detection package for CVE-2020-5902, a CVE10.0 vulnerability affecting F5 Networks, Inc BIG-IP devices.) (July 29, 2020)
- Exploit #3594 - CVE-2020-5902-Vuln-Checker (Simple Vulnerability Checker Wrote by me "@TheCyberViking" and A fellow Researcher who wanted to be left Nameless... you know who you are you beautiful bitch) (July 25, 2020)
- Exploit #3544 - CVE-2020-5902-rce-gui (GUI) (July 20, 2020)
- Exploit #3516 - cve-2020-5902-ioc-bigip-checker () (July 20, 2020)
- Exploit #3486 - CVE-2020-5902 (Proof of concept for CVE-2020-5902) (July 15, 2020)
- Exploit #3484 - CVE-2020-5902-NSE () (July 15, 2020)
- Exploit #3490 - F5-Patch (Patch F5 appliance CVE-2020-5902) (July 15, 2020)
- Exploit #3491 - CVE-2020-5902 (F5 BIG-IP Scanner (CVE-2020-5902)) (July 15, 2020)
- Exploit #3492 - CVE-2020-5902-fix (Fix CVE-2020-5902) (July 15, 2020)
- Exploit #3493 - CVE-2020-5902 (Python script to exploit F5 Big-IP CVE-2020-5902 ) (July 15, 2020)
- Exploit #3494 - CVE-2020-5902-F5BIG () (July 15, 2020)
- Exploit #3496 - CVE-2020-5902-Scanner (Automated script for F5 BIG-IP scanner (CVE-2020-5902) using hosts retrieved from Shodan API.) (July 15, 2020)
- Exploit #3497 - CVE-2020-5902-F5-BIGIP (Scan from a given list for F5 BIG-IP and check for CVE-2020-5902) (July 15, 2020)
- Exploit #3500 - CVE-2020-5902 (Python script to check CVE-2020-5902 (F5 BIG-IP devices).) (July 15, 2020)
- Exploit #3501 - CVE-2020-5902 (F5 BIG-IP 任意文件读取+远程命令执行RCE) (July 15, 2020)
- Exploit #3502 - CVE-2020-5902 (CVE-2020-5902) (July 15, 2020)
- Exploit #3483 - CVE-2020-5902 (CVE-2020-5902) (July 15, 2020)
- Exploit #3481 - F5-BIG-IP-CVE-2020-5902 () (July 15, 2020)
- Exploit #3480 - poc-CVE-2020-5902 (dummy poc) (July 15, 2020)
- Exploit #3479 - CVE-2020-5902_RCE () (July 15, 2020)
- Exploit #3478 - CVE-2020-5902 () (July 15, 2020)
- Exploit #3477 - scanner-CVE-2020-5902 (CVE-2020-5902 scanner) (July 15, 2020)
- Exploit #3476 - RCE-CVE-2020-5902 (BIG-IP F5 Remote Code Execution) (July 15, 2020)
- Exploit #3475 - CVE-2020-5902 () (July 15, 2020)
- Exploit #3473 - CVE-2020-5902 (POC code for checking for this vulnerability. Since the code has been released, I decided to release this one as well. Patch Immediately!) (July 15, 2020)
- Exploit #3470 - CVE-2020-5902 (CVE-2020-5902) (July 15, 2020)
- Exploit #3086 - CVE-2020-5902-POC-EXP (批量扫描CVE-2020-5902,远程代码执行,已测试) (July 15, 2020)
- Exploit #3072 - f5_scanner (F5 mass scanner and CVE-2020-5902 checker) (July 15, 2020)
- Exploit #3085 - CVE-2020-5902-fofa-scan () (July 15, 2020)
- Exploit #3084 - GoF5-CVE-2020-5902 (Script para validar CVE-2020-5902 hecho en Go.) (July 15, 2020)
- Exploit #3083 - cve-2020-5902 (cve-2020-5902 POC exploit) (July 15, 2020)
- Exploit #3082 - CVE-2020-5902 (POC) (July 15, 2020)
- Exploit #3081 - CVE-2020-5902 (CVE-2020-5902 Exploit) (July 15, 2020)
- Exploit #3080 - checkvulnCVE2020590 (A powershell script to check vulnerability CVE-2020-5902 of ip list) (July 15, 2020)
- Exploit #3079 - CVE-2020-5902 (exploit code for F5-Big-IP (CVE-2020-5902)) (July 15, 2020)
- Exploit #3078 - CVE-2020-5902 (Proof of Concept for CVE-2020-5902) (July 15, 2020)
- Exploit #3076 - CVE-2020-5902 () (July 15, 2020)
- Exploit #3074 - CVE-2020-5902 () (July 15, 2020)
- Exploit #3087 - CVE-2020-5902-POC (批量检测CVE-2020-5902) (July 15, 2020)
- Exploit #3089 - CVE-2020-5902 (Exploits for CVE-2020-5902 POC ) (July 15, 2020)
- Exploit #3090 - checker-CVE-2020-5902 (Checker CVE-2020-5902: BIG-IP versions 15.0.0 through 15.1.0.3, 14.1.0 through 14.1.2.5, 13.1.0 through 13.1.3.3, 12.1.0 through 12.1.5.1, and 11.6.1 through 11.6.5.1 suffer from Traffic Management User Interface (TMUI) arbitrary fi (July 15, 2020)
- Exploit #3091 - f5scan (F5 BIG IP Scanner for CVE-2020-5902) (July 15, 2020)
- Exploit #3093 - CVE-2020-5902-Mass (Mass exploit for CVE-2020-5902) (July 15, 2020)
- Exploit #3094 - EvilRip (It is a small script to fetch out the subdomains/ip vulnerable to CVE-2020-5902 written in bash) (July 15, 2020)
- Exploit #3095 - F5-Big-IP-CVE-2020-5902-mass-exploiter (F5 Big-IP CVE-2020-5902 mass exploiter/fuzzer.) (July 15, 2020)
- Exploit #3096 - CVE-2020-5902 (CVE-2020-5902) (July 15, 2020)
- Exploit #3098 - f5-bigip-rce-cve-2020-5902 (F5 BIG-IP RCE CVE-2020-5902 automatic check tool) (July 15, 2020)
- Exploit #3100 - cve-2020-5902 () (July 15, 2020)
- Exploit #3110 - CVE-2020-5902 (CVE-2020-5902 BIG-IP) (July 15, 2020)
- Exploit #3065 - F5 BIG-IP TMUI Directory Traversal and File Upload RCE (July 8, 2020)