OS Command Injection in F5 Networks products - CVE-2021-22986
Published: March 11, 2021 / Updated: March 7, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation within the iControl REST API. A remote unauthenticated attacker can send a specially crafted HTTP request to the affected API endpoint and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
BIG-IP SSLO
BIG-IP
BIG-IP DDHD
BIG-IP FPS
BIG-IP PEM
BIG-IP AFM
BIG-IP GTM
BIG-IP Analytics
BIG-IP APM
BIG-IP ASM
BIG-IP LTM
BIG-IP Advanced WAF
BIG-IP DNS
BIG-IP Link Controller
BIG-IP AAM
How to mitigate CVE-2021-22986
BIG-IP SSLO - addressed in versions 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1
BIG-IP FPS - addressed in versions 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1
BIG-IP PEM - addressed in versions 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1
BIG-IP AFM - addressed in versions 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1
BIG-IP GTM - addressed in versions 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1
BIG-IP Analytics - addressed in versions 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1
BIG-IP - addressed in versions 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1
BIG-IP APM - addressed in versions 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1
BIG-IP Advanced WAF - addressed in versions 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1
BIG-IP DNS - addressed in versions 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1
BIG-IP Link Controller - addressed in versions 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1
BIG-IP DDHD - addressed in versions 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1
BIG-IP ASM - addressed in versions 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1
BIG-IP LTM - addressed in versions 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1
BIG-IP AAM - addressed in versions 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1
Links to Public Exploits and PoC-codes
- Exploit #11195 - CVE-2021-22986 (F5 BIG-IP/BIG-IQ iControl Rest API SSRF to RCE) (March 7, 2025)
- Exploit #7908 - F5-BIG-IP-POC (CVE-2020-5902 CVE-2021-22986 CVE-2022-1388 POC集合) (May 29, 2022)
- Exploit #6545 - F5_RCE (CVE-2021-22986 F5 BIG-IP iControl 命令执行漏洞) (July 19, 2021)
- Exploit #6497 - CVE-2021-22986-Poc (This is a Poc for BIGIP iControl unauth RCE ) (July 1, 2021)
- Exploit #5555 - CVE-2021-22986 (Code By:Tas9er / F5 BIG-IP 远程命令执行漏洞) (June 10, 2021)
- Exploit #5490 - f5_rce_poc (cve-2021-22986 f5 rce 漏洞批量检测 poc) (May 26, 2021)
- Exploit #5477 - CVE-2021-22986-SSRF2RCE (F5 BIG-IP/BIG-IQ iControl Rest API SSRF to RCE) (May 24, 2021)
- Exploit #5471 - CVE-2021-22986 (CVE-2021-22986 & F5 BIG-IP RCE) (May 24, 2021)
- Exploit #5427 - CVE-202122986-EXP (F5 BIG-IP远程代码执行;cve-2021-22986,批量检测;命令执行利用) (May 18, 2021)
- Exploit #5393 - F5 BIG-IP 16.0.x - iControl REST Remote Code Execution (Unauthenticated) (May 9, 2021)
- Exploit #5374 - F5 iControl REST Unauthenticated SSRF Token Generation RCE (May 9, 2021)
- Exploit #5296 - CVE-2021-22986_F5_BIG_IP_GUI_Exploit () (April 16, 2021)