When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenti...
Description
When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: F5
PRODUCT: BIG-IP
AFFECTED_VERSIONS: 21.0.0 up to (excluding) 21.0.0.1, 17.5.0 up to (excluding) 17.5.1.4, 17.1.0 up to (excluding) 17.1.3.1, 16.1.0 and later
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A command injection vulnerability in F5 BIG-IP allows authenticated administrators to execute arbitrary system commands via iControl REST or the TMOS Shell.
Executive Summary:
A critical command injection vulnerability exists in F5 BIG-IP that allows an authenticated administrator to execute arbitrary system commands, potentially leading to full system compromise.
Vulnerability Details
CVE-ID: CVE-2026-40061
Affected Software: F5 BIG-IP
Affected Versions: 21.0.0 up to (excluding) 21.0.0.1, 17.5.0 up to (excluding) 17.5.1.4, 17.1.0 up to (excluding) 17.1.3.1, 16.1.0 and later
Vulnerability: This vulnerability involves improper neutralization of special elements used in a command (CWE-77). It requires an authenticated attacker with Resource Administrator or Administrator privileges to trigger the flaw via iControl REST or the TMOS Shell.
Business Impact
Successful exploitation allows an attacker with elevated administrative access to execute arbitrary commands at the system level. Given the CVSS score of 8.7, this represents a high risk to the confidentiality and integrity of the BIG-IP appliance, which often serves as a critical gateway for network traffic and security services.
Remediation Plan
Immediate Action: Upgrade to version 21.1.0 or later, or apply the specific version updates provided by F5 in security advisory K000160788.
Proactive Monitoring: Review TMOS Shell and iControl REST logs for unauthorized or suspicious command sequences executed by administrative accounts.
Compensating Controls: Restrict access to management interfaces to trusted IP addresses and enforce strict role-based access control (RBAC) to minimize the number of users with administrative privileges.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of May 14, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. While the vulnerability requires existing administrative privileges, the ability to escalate to system-level command execution makes it a high-risk vector for malicious insiders or compromised admin accounts.
Analyst Recommendation
Organizations should prioritize patching F5 BIG-IP appliances immediately. Given the high severity of command injection, ensuring that all affected systems are updated to the vendor-recommended versions is essential to preventing potential unauthorized system-level control.