CVE-2021-22986
CRITICAL KEV RANSOMWARE NUCLEIF5 iControl REST Unauthenticated SSRF Token Generation RCE
Title source: metasploitDescription
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Exploits (22)
nomisec
WORKING POC
51 stars
by dorkerdevil · remote
https://github.com/dorkerdevil/CVE-2021-22986-Poc
nomisec
SUSPICIOUS
by whatheheckisthis · poc
https://github.com/whatheheckisthis/Canonical-Extension-CVE-2021-22986
nomisec
WRITEUP
by whatheheckisthis · poc
https://github.com/whatheheckisthis/BigIP-iControl-RCE-Research
nomisec
WRITEUP
by whatheheckisthis · poc
https://github.com/whatheheckisthis/bigip-icontrol-rce-research
metasploit
WORKING POC
EXCELLENT
by wvu, Rich Warren · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/f5_icontrol_rest_ssrf_rce.rb
Nuclei Templates (1)
F5 iControl REST - Remote Command Execution
CRITICALby rootxharsh,iamnoooob
Shodan:
http.title:"big-ip®-+redirect" +"server"
FOFA:
title="big-ip®-+redirect" +"server"
References (4)
Scores
CVSS v3
9.8
EPSS
0.9448
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2021-11-03
VulnCheck KEV
2021-06-01
InTheWild.io
2021-03-20
ENISA EUVD
EUVD-2021-10104
Ransomware Use
Confirmed
CWE
CWE-918
Status
published
Products (15)
f5/big-ip_access_policy_manager
12.1.0 - 12.1.5.3
f5/big-ip_advanced_firewall_manager
12.1.0 - 12.1.5.3
f5/big-ip_advanced_web_application_firewall
12.1.0 - 12.1.5.3
f5/big-ip_analytics
12.1.0 - 12.1.5.3
f5/big-ip_application_acceleration_manager
12.1.0 - 12.1.5.3
f5/big-ip_application_security_manager
12.1.0 - 12.1.5.3
f5/big-ip_ddos_hybrid_defender
12.1.0 - 12.1.5.3
f5/big-ip_domain_name_system
12.1.0 - 12.1.5.3
f5/big-ip_fraud_protection_service
12.1.0 - 12.1.5.3
f5/big-ip_global_traffic_manager
12.1.0 - 12.1.5.3
... and 5 more
Published
Mar 31, 2021
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026