Description
This module exploits a directory traversal in F5's BIG-IP Traffic Management User Interface (TMUI) to upload a shell script and execute it as the Unix root user.
Unix shell access is obtained by escaping the restricted Traffic Management Shell (TMSH). The escape may not be reliable, and you may have to run the exploit multiple times. Sorry!
Versions 11.6.1-11.6.5, 12.1.0-12.1.5, 13.1.0-13.1.3, 14.1.0-14.1.2, 15.0.0, and 15.1.0 are known to be vulnerable. Fixes were introduced in 11.6.5.2, 12.1.5.2, 13.1.3.4, 14.1.2.6, and 15.1.0.4.
Tested against the VMware OVA release of 14.1.2.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/http/f5_bigip_tmui_rce_cve_2020_5902msf undefined(f5_bigip_tmui_rce_cve_2020_5902) > show actions ...actions...msf undefined(f5_bigip_tmui_rce_cve_2020_5902) > set ACTION < action-name >msf undefined(f5_bigip_tmui_rce_cve_2020_5902) > show options ...show and set options...msf undefined(f5_bigip_tmui_rce_cve_2020_5902) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub