CVE-2021-22986
F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability
- Published
- Mar 31, 2021
- Updated
- Oct 21, 2025
- Assigning CNA
- f5
- Evidence observed
- Apr 2, 2021
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 100.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Sources
16- PocListPoC
Vulnerability-specific PoC scripts for discovering and exploiting RCE, SQLi, XXE, SSRF, and unauthorized-access flaws in enterprise web apps and middleware.
- CVE-2021-22986Exploit
CVE-2021-22986 & F5 BIG-IP RCE
- CVE-2021-22986Exploit
Python exploit for CVE-2021-22986, enabling unauthenticated RCE on F5 BIG-IP and BIG-IQ via iControl REST, with command execution, batch scanning, and reverse shell features.
This is a Poc for BIGIP iControl unauth RCE
- CVE-2021-22986Scanner
Script to check mass IP addresses for CVE-2021-22986 vulnerability using Shodan or ZoomEye for IP discovery.
- CVE-2021-22986Exploit
Python exploit script for CVE-2021-22986, targeting a remote code execution vulnerability in F5 BIG-IP devices. Provides URL-based exploitation for penetration testing and red team assessments.
- CVE-2021-22986Exploit
F5 BIG-IP/BIG-IQ iControl Rest API SSRF to RCE
CVE-2020-5902 CVE-2021-22986 CVE-2022-1388 PoC Collection
- CVE-2021-22986Exploit
Exploit for CVE-2021-22986 targeting F5 BIG-IP, enabling unauthenticated remote code execution on vulnerable systems.
Proof-of-concept exploit for CVE-2021-22986, targeting a remote code execution vulnerability in F5 BIG-IP iControl REST interface.
A vulnerability scanner that detects CVE-2021-22986 vulnerabilities.
- f5_rce_pocPoC
cve-2021-22986 f5 rce 漏洞批量检测 poc
- F5_RCEExploit
CVE-2021-22986 F5 BIG-IP iControl command execution vulnerability
- CVE-2021-22986Exploit
Code By:Tas9er / F5 BIG-IP 远程命令执行漏洞
- CVE-202122986-EXPExploit
F5 BIG-IP远程代码执行;cve-2021-22986,批量检测;命令执行利用
Al1ex · hardware · Apr 2, 2021
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.