Vulnerability record · CVE-2020-5902 · published 1 July 2020
CVE-2020-5902: F5 BIG-IP TMUI path traversal leading to remote code execution
F5 · Big Ip Access Policy Manager
The F5 BIG-IP Traffic Management User Interface (TMUI, also called the Configuration utility) contains a path traversal flaw (CWE-22) in undisclosed pages that allows remote code execution. It affects BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1 across many BIG-IP modules. Because TMUI is the management interface of a widely deployed edge device, successful exploitation gives an attacker control of a system that sits in front of protected applications.
Description
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE on edge devices, listed in CISA KEV with known ransomware use and an EPSS probability near 1.0.
What it is
The F5 BIG-IP Traffic Management User Interface (TMUI, also called the Configuration utility) contains a path traversal flaw (CWE-22) in undisclosed pages that allows remote code execution. It affects BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1 across many BIG-IP modules. Because TMUI is the management interface of a widely deployed edge device, successful exploitation gives an attacker control of a system that sits in front of protected applications.
Impact
An unauthenticated attacker can execute arbitrary code on the BIG-IP system, gaining full control of the device (CVSS 3.1 9.8, C:H/I:H/A:H). That control can be used to read or alter configuration, intercept or redirect traffic, and pivot into networks the device protects.
Attack surface
Reached over the network via the TMUI/Configuration utility web interface; the CVSS vector AV:N/AC:L/PR:N/UI:N indicates no authentication and no user interaction are required. Exposure is limited to deployments where the management interface is reachable, so internet-facing TMUI is the primary risk.
Exploitation
Exploitation is confirmed: CVE-2020-5902 is in CISA KEV (added 2021-11-03, known ransomware campaign use) and EPSS 30-day probability is 0.99999 (percentile 1). Multiple references are tagged Exploit, including public proof-of-concept and checker tooling.
What to do
- Apply the F5 vendor updates for the affected BIG-IP versions per F5 advisory K52145254.
- Restrict access to the TMUI/Configuration utility to trusted management networks; do not expose it to the internet.
- If patching is delayed, apply F5's documented mitigation guidance for this issue and monitor for changes.
- Rotate credentials and review configuration on any BIG-IP that may have been exposed, since code execution implies full device compromise.
- Inventory all BIG-IP instances and modules to confirm none remain on the affected version ranges.
Detection
- Hunt web/proxy logs for TMUI requests containing path traversal sequences (for example ../ or encoded variants) targeting the Configuration utility.
- Alert on unexpected outbound connections or new processes/files on BIG-IP systems, which can indicate post-exploitation activity.
- Monitor for access to TMUI from untrusted or internet-routed source addresses.
- Use the public checker/PoC references to validate exposure of internet-facing BIG-IP management interfaces.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-5902 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-5902 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-5902), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.