
CVE-2022-1388, bypassing iControl REST authentication
This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.
./CVE-2022-1388.sh <ip_addr>

https://support.f5.com/csp/article/K23605346
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-1388
⚠️ Any malicious use of the contents from this repo will not hold the author responsible, the contents are solely for educational purpose.