Security Research

CVE-2020-5902 F5 BIG-IP TMUI RCE: From File Read to Root Command Execution

#Vulnerability Analysis#Code Audit#Network Attack
Directory traversal and tmsh hidden commands in F5 TMUI

F5 BIG-IP’s TMUI hides an entire layer of “undocumented interfaces” — CVE-2020-5902 exposed the cost of that layer: an unauthenticated remote attacker directly gets a root shell.

Unlock to view this content.