CVE-2020-5902

F5 BIG-IP: Traffic Management User Interface (TMUI) Remote Code Execution

As of , CVE-2020-5902 in F5 BIG-IP is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 3 November 2021
US federal deadline
3 May 2022181 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Known
EPSS score
0.99Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
Not availableCISA listed it before 4 February 2022, where the EPSS files we read begin.
Public exploit
1 Metasploit module and 3 Exploit-DB entries
Fix
No vendor link in CISA's entry

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.

CISA's description

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.

The CVE record's description, from f5

CVE published
1 July 2020
Assigned by
f5
CVSS
9.8 Critical (CVSS 3.1, from CISA-ADP)
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. Exploit-DB published an exploit (EDB-ID 48643).
  3. Exploit-DB published an exploit (EDB-ID 48642).
  4. Exploit-DB published an exploit (EDB-ID 48711).
  5. CISA added it to its list of exploited vulnerabilities.
  6. The US federal deadline to fix it.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

BIG-IP: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2022-1388Missing AuthenticationF5 BIG-IPPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2025-53521Stack-Based Buffer OverflowF5 BIG-IPPatch soon0.02

Read further