CVE-2020-5902

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface...

Basic Information

CVE State
PUBLISHED
Reserved Date
January 06, 2020
Published Date
July 01, 2020
Last Updated
January 29, 2025
Vendor
n/a
Product
BIG-IP
Description
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.

CVSS Scores

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2021-11-03 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2020-07-07 11:31:31 UTC) Source
Used in Malware
Yes (added 2021-11-03 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2021-11-03 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

f5_bigip_tmui_rce_cve_2020_5902

Type: metasploit • Created: Unknown

Metasploit module for CVE-2020-5902

amitlttwo/CVE-2020-5902

Type: github • Created: 2023-02-07 11:07:23 UTC • Stars: 1

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.

z3n70/CVE-2020-5902

Type: github • Created: 2022-07-07 14:48:08 UTC • Stars: 2

BIGIP CVE-2020-5902 Exploit POC and automation scanning vulnerability

haisenberg/CVE-2020-5902

Type: github • Created: 2021-04-13 06:48:20 UTC • Stars: 1

Auto exploit RCE CVE-2020-5902

faisalfs10x/F5-BIG-IP-CVE-2020-5902-shodan-scanner

Type: github • Created: 2021-02-04 16:36:21 UTC • Stars: 1

simple bash script of F5 BIG-IP TMUI Vulnerability CVE-2020-5902 checker

murataydemir/CVE-2020-5902

Type: github • Created: 2020-08-13 08:27:25 UTC • Stars: 2

[CVE-2020-5902] F5 BIG-IP Remote Code Execution (RCE)

PushpenderIndia/CVE-2020-5902-Scanner

Type: github • Created: 2020-08-09 11:46:23 UTC • Stars: 13

Automated F5 Big IP Remote Code Execution (CVE-2020-5902) Scanner Written In Python 3

corelight/CVE-2020-5902-F5BigIP

Type: github • Created: 2020-07-28 00:43:14 UTC • Stars: 4

A network detection package for CVE-2020-5902, a CVE10.0 vulnerability affecting F5 Networks, Inc BIG-IP devices.

rockmelodies/CVE-2020-5902-rce-gui

Type: github • Created: 2020-07-17 03:13:30 UTC • Stars: 8

GUI

Al1ex/CVE-2020-5902

Type: github • Created: 2020-07-11 14:01:08 UTC • Stars: 10

CVE-2020-5902

MrCl0wnLab/checker-CVE-2020-5902

Type: github • Created: 2020-07-10 07:00:35 UTC • Stars: 5

Checker CVE-2020-5902: BIG-IP versions 15.0.0 through 15.1.0.3, 14.1.0 through 14.1.2.5, 13.1.0 through 13.1.3.3, 12.1.0 through 12.1.5.1, and 11.6.1 through 11.6.5.1 suffer from Traffic Management User Interface (TMUI) arbitrary file read and command execution vulnerabilities.

d4rk007/F5-Big-IP-CVE-2020-5902-mass-exploiter

Type: github • Created: 2020-07-09 08:34:37 UTC • Stars: 4

F5 Big-IP CVE-2020-5902 mass exploiter/fuzzer.

deepsecurity-pe/GoF5-CVE-2020-5902

Type: github • Created: 2020-07-09 06:09:39 UTC • Stars: 2

Script para validar CVE-2020-5902 hecho en Go.

dnerzker/CVE-2020-5902

Type: github • Created: 2020-07-08 16:22:53 UTC • Stars: 0

zhzyker/CVE-2020-5902

Type: github • Created: 2020-07-08 04:02:07 UTC • Stars: 13

F5 BIG-IP 任意文件读取+远程命令执行RCE

ajdumanhug/CVE-2020-5902

Type: github • Created: 2020-07-07 19:07:55 UTC • Stars: 0

POC

k3nundrum/CVE-2020-5902

Type: github • Created: 2020-07-07 11:31:31 UTC • Stars: 0

0xAbdullah/CVE-2020-5902

Type: github • Created: 2020-07-06 14:41:29 UTC • Stars: 1

Python script to check CVE-2020-5902 (F5 BIG-IP devices).

lijiaxing1997/CVE-2020-5902-POC-EXP

Type: github • Created: 2020-07-06 09:16:36 UTC • Stars: 10

批量扫描CVE-2020-5902,远程代码执行,已测试

cybersecurityworks553/scanner-CVE-2020-5902

Type: github • Created: 2020-07-06 06:58:29 UTC • Stars: 2

CVE-2020-5902 scanner

sv3nbeast/CVE-2020-5902_RCE

Type: github • Created: 2020-07-06 06:45:21 UTC • Stars: 8

dunderhay/CVE-2020-5902

Type: github • Created: 2020-07-06 04:03:58 UTC • Stars: 37

Python script to exploit F5 Big-IP CVE-2020-5902

yasserjanah/CVE-2020-5902

Type: github • Created: 2020-07-06 01:12:23 UTC • Stars: 43

exploit code for F5-Big-IP (CVE-2020-5902)

nsflabs/CVE-2020-5902

Type: github • Created: 2020-07-05 20:16:07 UTC • Stars: 8

rwincey/CVE-2020-5902-NSE

Type: github • Created: 2020-07-05 17:51:38 UTC • Stars: 8

yassineaboukir/CVE-2020-5902

Type: github • Created: 2020-07-05 17:01:27 UTC • Stars: 72

Proof of concept for CVE-2020-5902

ar0dd/CVE-2020-5902

Type: github • Created: 2020-07-05 16:38:36 UTC • Stars: 12

POC code for checking for this vulnerability. Since the code has been released, I decided to release this one as well. Patch Immediately!

jas502n/CVE-2020-5902

Type: github • Created: 2020-07-05 16:38:32 UTC • Stars: 373

CVE-2020-5902 BIG-IP

aqhmal/CVE-2020-5902-Scanner

Type: github • Created: 2020-07-05 06:19:09 UTC • Stars: 55

Automated script for F5 BIG-IP scanner (CVE-2020-5902) using hosts retrieved from Shodan API.

dwisiswant0/CVE-2020-5902

Type: github • Created: 2020-07-04 14:12:57 UTC • Stars: 9

CVE-2020-5902