Authentication bypass using an alternate path or channel in BIG-IP and BIG-IQ Centralized Management - CVE-2023-46747
Published: October 27, 2023 / Updated: December 12, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper authentication in the Configuration utility. A remote non-authenticated attacker can send a specially crafted requests to the system, bypass authentication and execute arbitrary commands on the device.
Affected software
BIG-IQ Centralized Management
BIG-IP Next Central Manager
How to mitigate CVE-2023-46747
BIG-IQ Centralized Management - update to cvssv3 score
Links to Public Exploits and PoC-codes
- Exploit #12194 - F5-BIG-IP-SmuggleShell-CVE-2023-46747-Exploit (#F5-BIG-IP-CVE-2023-46747-Exploit – Unauthenticated RCE Python exploit & Nuclei template by Raguraman ✓ Automated TCP reverse shell (LHOST/LPORT) ✓ Tested on affected BIG-IP 13.x–17.x ⚠️ Authorized pe (December 12, 2025)
- Exploit #11208 - cve-2023-46747 () (March 14, 2025)
- Exploit #11170 - CVE-2023-46747 (An Exploitation script developed to exploit the CVE-2023-46747 which Pre Auth Remote Code Execution of f5-BIG Ip producs) (February 25, 2025)
- Exploit #10805 - CVE-2023-46747-RCE-poc () (November 5, 2024)
- Exploit #9797 - test_cve-2023-46747 () (May 13, 2024)
- Exploit #9438 - CVE-2023-46747-RCE (exploit for f5-big-ip RCE cve-2023-46747) (December 19, 2023)
- Exploit #9401 - F5 BIG-IP TMUI AJP Smuggling RCE (November 2, 2023)