F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability (CWE-863, improper authorization check) in the iControl REST interface. An unauthenticated attacker with network access to the REST endpoint can send crafted requests to execute arbitrary system commands, create or delete files, and disable services on the appliance or virtual instance. Successful exploitation effectively gives the attacker command-level control of the underlying F5 system, which is sufficient for account creation, persistence, lateral movement, and ransomware staging. Any organization running affected BIG-IP or BIG-IQ releases is exposed, particularly where the management interface or iControl REST is reachable from untrusted networks. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2021-11-03 with known ransomware use, EPSS places the 30-day exploitation probability at 99.9% (top percentile), though no public PoC is cataloged.
What to do: Upgrade BIG-IP and BIG-IQ to the fixed releases identified in F5's advisory (K03051234) on an urgent basis, since exploitation is in the wild and ransomware actors use this flaw. Until patched, restrict network access to the management interface and iControl REST to trusted administration networks. Because ransomware use is known, review affected devices for indicators of compromise such as unexpected commands, created or deleted files, and disabled services.
Affected
F5 BIG-IP
—
F5 BIG-IQ Centralized Management
—
Estimated exposure
largetens of thousands of internet-exposed BIG-IP management interfaces (public scan counts at disclosure), within a total installed base of hundreds of thousands… — Public internet scans around disclosure time showed tens of thousands of F5 BIG-IP devices with exposed management/REST endpoints, against a much larger enterprise and data-center installed base where iControl REST is often only reachable…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Hackers exploited Fortinet CVE-2024-21762 RCE to breach Thai broadband provider 3BB, deploying MeshCentral backdoors and credential-harvesting tools across its network.
Hunt.io uncovered an intrusion staging directory in Thailand containing 298 files of custom tooling built for Triple T Broadband (3BB) and its former owner Jasmine. Initial access came via fingerprinting a FortiGate SSL-VPN appliance and exploiting CVE-2024-21762 for remote code execution, after probing CVE-2018-13379, CVE-2022-42475, and CVE-2023-27997. The actor also probed F5 BIG-IP for CVE-2021-22986, CVE-2022-1388, and CVE-2023-46747, escalated privileges with PwnKit and Dirty COW, used MeshCentral as a C2 backdoor, harvested SSH/database/SNMP/Radius credentials, deployed PHP web shells, and ran cleanup scripts to hide the intrusion.