CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

PUBLISHEDvulnerability record
2021-11-03 · last modified June 21, 2025

Metadata

CVE ID:
CVE-2021-22986
Project:
F5
Product:
BIG-IP and BIG-IQ Centralized Management
Date Added:
2021-11-03
Due Date:
2021-11-17
Last Updated:
June 21, 2025

Vulnerability Name

F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

Description

F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
KNOWN

Action

Apply updates per vendor instructions.

Additional Notes

Related Weaknesses