CVE-2022-1388

CRITICAL KEV RANSOMWARE NUCLEI

F5 BIG-IP iControl RCE via REST Authentication Bypass

Title source: metasploit

Description

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Exploits (76)

nomisec WORKING POC 231 stars
by horizon3ai · remote
https://github.com/horizon3ai/CVE-2022-1388
nomisec WORKING POC 92 stars
by doocop · poc
https://github.com/doocop/CVE-2022-1388-EXP
nomisec WORKING POC 87 stars
by alt3kx · remote
https://github.com/alt3kx/CVE-2022-1388_PoC
nomisec WORKING POC 83 stars
by 0xf4n9x · remote
https://github.com/0xf4n9x/CVE-2022-1388
nomisec WORKING POC 59 stars
by ZephrFish · remote
https://github.com/ZephrFish/F5-CVE-2022-1388-Exploit
nomisec WORKING POC 58 stars
by sherlocksecurity · poc
https://github.com/sherlocksecurity/CVE-2022-1388-Exploit-POC
nomisec WORKING POC 54 stars
by numanturle · remote
https://github.com/numanturle/CVE-2022-1388
nomisec WORKING POC 37 stars
by Al1ex · remote
https://github.com/Al1ex/CVE-2022-1388
nomisec SCANNER 28 stars
by MrCl0wnLab · infoleak
https://github.com/MrCl0wnLab/Nuclei-Template-CVE-2022-1388-BIG-IP-iControl-REST-Exposed
nomisec SCANNER 25 stars
by jheeree · remote
https://github.com/jheeree/CVE-2022-1388-checker
nomisec WORKING POC 14 stars
by PsychoSec2 · remote
https://github.com/PsychoSec2/CVE-2022-1388-POC
nomisec WORKING POC 14 stars
by justakazh · remote
https://github.com/justakazh/CVE-2022-1388
nomisec WORKING POC 12 stars
by Zeyad-Azima · remote
https://github.com/Zeyad-Azima/CVE-2022-1388
nomisec WORKING POC 10 stars
by west9b · remote
https://github.com/west9b/F5-BIG-IP-POC
nomisec WORKING POC 8 stars
by qusaialhaddad · remote
https://github.com/qusaialhaddad/F5-BigIP-CVE-2022-1388
nomisec WORKING POC 8 stars
by Henry4E36 · remote
https://github.com/Henry4E36/CVE-2022-1388
nomisec SCANNER 7 stars
by blind-intruder · poc
https://github.com/blind-intruder/CVE-2022-1388-RCE-checker-and-POC-Exploit
nomisec WORKING POC 7 stars
by vaelwolf · remote
https://github.com/vaelwolf/CVE-2022-1388
nomisec WRITEUP 6 stars
by Vulnmachines · remote
https://github.com/Vulnmachines/F5-Big-IP-CVE-2022-1388
nomisec WORKING POC 6 stars
by MrCl0wnLab · poc
https://github.com/MrCl0wnLab/Nuclei-Template-Exploit-F5-BIG-IP-iControl-REST-Auth-Bypass-RCE-Command-Parameter
nomisec WORKING POC 6 stars
by 0x7eTeam · poc
https://github.com/0x7eTeam/CVE-2022-1388-PocExp
nomisec SCANNER 5 stars
by AmirHoseinTangsiriNET · remote
https://github.com/AmirHoseinTangsiriNET/CVE-2022-1388-Scanner
nomisec WORKING POC 5 stars
by Stonzyy · remote
https://github.com/Stonzyy/Exploit-F5-CVE-2022-1388
nomisec SCANNER 5 stars
by gotr00t0day · remote
https://github.com/gotr00t0day/CVE-2022-1388
nomisec WORKING POC 5 stars
by Angus-Team · remote
https://github.com/Angus-Team/F5-BIG-IP-RCE-CVE-2022-1388
nomisec WORKING POC 4 stars
by bandit92 · poc
https://github.com/bandit92/CVE2022-1388_TestAPI
nomisec WORKING POC 3 stars
by nvk0x · remote
https://github.com/nvk0x/CVE-2022-1388-exploit
nomisec WORKING POC 3 stars
by revanmalang · remote
https://github.com/revanmalang/CVE-2022-1388
nomisec WORKING POC 2 stars
by devengpk · remote
https://github.com/devengpk/CVE-2022-1388
nomisec WORKING POC 2 stars
by superzerosec · remote
https://github.com/superzerosec/CVE-2022-1388
nomisec SCANNER 2 stars
by SecTheBit · remote
https://github.com/SecTheBit/CVE-2022-1388
nomisec WORKING POC 2 stars
by savior-only · remote
https://github.com/savior-only/CVE-2022-1388
nomisec WORKING POC 2 stars
by saucer-man · remote
https://github.com/saucer-man/CVE-2022-1388
github WORKING POC 2 stars
by Pr0t0c01 · pythonpoc
https://github.com/Pr0t0c01/CVEs/tree/main/BigIP_CVE-2022-1388
nomisec WORKING POC 2 stars
by aancw · remote
https://github.com/aancw/CVE-2022-1388-rs
nomisec SCANNER 2 stars
by EvilLizard666 · remote
https://github.com/EvilLizard666/CVE-2022-1388
nomisec WORKING POC 1 stars
by ThinkingOffensively · poc
https://github.com/ThinkingOffensively/CVE-2022-1388
nomisec WORKING POC 1 stars
by amitlttwo · remote
https://github.com/amitlttwo/CVE-2022-1388
nomisec WORKING POC 1 stars
by iveresk · remote
https://github.com/iveresk/cve-2022-1388-1veresk
nomisec WORKING POC 1 stars
by j-baines · remote
https://github.com/j-baines/tippa-my-tongue
nomisec WORKING POC 1 stars
by chesterblue · remote
https://github.com/chesterblue/CVE-2022-1388
nomisec WORKING POC 1 stars
by nico989 · remote
https://github.com/nico989/CVE-2022-1388
nomisec WORKING POC 1 stars
by Luchoane · remote
https://github.com/Luchoane/CVE-2022-1388_refresh
nomisec WORKING POC 1 stars
by Chocapikk · remote
https://github.com/Chocapikk/CVE-2022-1388
nomisec WORKING POC 1 stars
by 0xAgun · remote
https://github.com/0xAgun/CVE-2022-1388
nomisec WORKING POC 1 stars
by vesperp · poc
https://github.com/vesperp/CVE-2022-1388-F5-BIG-IP
nomisec WORKING POC 1 stars
by iveresk · remote
https://github.com/iveresk/cve-2022-1388-iveresk-command-shell
nomisec WORKING POC 1 stars
by yukar1z0e · remote
https://github.com/yukar1z0e/CVE-2022-1388
nomisec WORKING POC 1 stars
by shamo0 · remote
https://github.com/shamo0/CVE-2022-1388
nomisec WORKING POC 1 stars
by thatonesecguy · remote
https://github.com/thatonesecguy/CVE-2022-1388-Exploit
nomisec WORKING POC 1 stars
by LinJacck · remote
https://github.com/LinJacck/CVE-2022-1388-EXP
github WORKING POC
by mangjong · pythonpoc
https://github.com/mangjong/Collection-of-PoC/tree/main/CVE/CVE-2022-1388.py
nomisec SCANNER
by mr-vill4in · remote
https://github.com/mr-vill4in/CVE-2022-1388
nomisec WORKING POC
by pauloink · remote
https://github.com/pauloink/CVE-2022-1388
nomisec WORKING POC
by jbharucha05 · remote
https://github.com/jbharucha05/CVE-2022-1388
nomisec SCANNER
by M4fiaB0y · remote
https://github.com/M4fiaB0y/CVE-2022-1388
nomisec SCANNER
by Hudi233 · remote
https://github.com/Hudi233/CVE-2022-1388
nomisec WORKING POC
by battleofthebots · remote
https://github.com/battleofthebots/refresh
gitlab WORKING POC
by t0adsec · remote
https://gitlab.com/t0adsec/cve-2022-1388-poc
nomisec WORKING POC
by li8u99 · poc
https://github.com/li8u99/CVE-2022-1388
nomisec WORKING POC
by impost0r · remote
https://github.com/impost0r/CVE-2022-1388
nomisec WORKING POC
by r0otk3r · remote
https://github.com/r0otk3r/CVE-2022-1388
nomisec WORKING POC
by On-Cyber-War · remote
https://github.com/On-Cyber-War/CVE-2022-1388
nomisec WORKING POC
by omnigodz · remote
https://github.com/omnigodz/CVE-2022-1388
nomisec WORKING POC
by sashka3076 · poc
https://github.com/sashka3076/F5-BIG-IP-exploit
nomisec SCANNER
by Osyanina · poc
https://github.com/Osyanina/westone-CVE-2022-1388-scanner
nomisec WORKING POC
by Wrin9 · poc
https://github.com/Wrin9/CVE-2022-1388
nomisec NO CODE
by SudeepaShiranthaka · poc
https://github.com/SudeepaShiranthaka/F5-BIG-IP-Remote-Code-Execution-Vulnerability-CVE-2022-1388-A-Case-Study
vulncheck_xdb WORKING POC
remote
https://github.com/vesperp/CVE-2022-1388-F5-BIG-IP-
vulncheck_xdb WORKING POC
remote
https://github.com/forktheplanet/CVE-2022-1388
exploitdb WORKING POC
by Yesith Alvarez · pythonremotemultiple
https://www.exploit-db.com/exploits/50932
metasploit WORKING POC EXCELLENT
by Heyder Andrade · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/f5_icontrol_rce.rb
vulncheck_xdb WORKING POC
remote
https://github.com/sherlocksecurity/CVE-2022-1388_F5_BIG-IP
vulncheck_xdb WORKING POC
remote
https://github.com/MrCl0wnLab/Nuclei-Template-Exploit-CVE-2022-1388-BIG-IP-iControl-REST
vulncheck_xdb WORKING POC
remote
https://github.com/v4sh25/CVE_2022_1388

Nuclei Templates (1)

F5 BIG-IP iControl - REST Auth Bypass RCE
CRITICALVERIFIEDby dwisiswant0,Ph33r
Shodan: http.title:"BIG-IP®-+Redirect" +"Server" || http.title:"big-ip®-+redirect" +"server"
FOFA: title="big-ip®-+redirect" +"server"

Scores

CVSS v3 9.8
EPSS 0.9446
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2022-05-10
VulnCheck KEV 2021-09-23
InTheWild.io 2022-05-08
ENISA EUVD EUVD-2022-24705
Ransomware Use Confirmed

Classification

CWE
CWE-306
Status published

Affected Products (11)

f5/big-ip_access_policy_manager < 11.6.5
f5/big-ip_advanced_firewall_manager < 11.6.5
f5/big-ip_analytics < 11.6.5
f5/big-ip_application_acceleration_manager < 11.6.5
f5/big-ip_application_security_manager < 11.6.5
f5/big-ip_domain_name_system < 11.6.5
f5/big-ip_fraud_protection_service < 11.6.5
f5/big-ip_global_traffic_manager < 11.6.5
f5/big-ip_link_controller < 11.6.5
f5/big-ip_local_traffic_manager < 11.6.5
f5/big-ip_policy_enforcement_manager < 11.6.5

Timeline

Published May 05, 2022
KEV Added May 10, 2022
Tracked Since Feb 18, 2026