F5 Networks

F5 Networks

Top 100 site
Bounty Partial Safe Harbor

Known Exploited Vulnerabilities 7CVEs

4 linked to ransomware campaigns

  • CVE-2025-53521BIG-IPMar 27, 20262.3% EPSS

    F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.

  • CVE-2023-46748BIG-IP Configuration UtilityOct 31, 20234.5% EPSS

    F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747.

  • CVE-2023-46747BIG-IP Configuration UtilityOct 31, 202396.5% EPSS

    F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.

  • CVE-2022-1388BIG-IPMay 10, 2022100.0% EPSS

    F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.

  • CVE-2021-22991BIG-IP Traffic Management MicrokernelJan 18, 202261.1% EPSS

    The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.

  • CVE-2020-5902BIG-IPNov 3, 2021100.0% EPSS

    F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.

  • CVE-2021-22986BIG-IP and BIG-IQ Centralized ManagementNov 3, 202199.9% EPSS

    F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.

security.txt

Contact
https://my.f5.com/manage/s/article/K4602#proc1
Encryption
https://my.f5.com/manage/s/article/K4602#PGP
Policy
https://my.f5.com/manage/s/article/K4602
Hiring
https://www.f5.com/company/careers
Expires
Aug 31, 2027
View raw security.txt →