Vulnerability record · CVE-2021-22986 · published 31 March 2021
CVE-2021-22986: F5 BIG-IP iControl REST unauthenticated remote command execution
F5 · Big Ip Access Policy Manager
The iControl REST interface on multiple F5 BIG-IP and BIG-IQ versions exposes an unauthenticated remote command execution flaw, tracked as CWE-918 server-side request forgery. Because the interface is reachable without credentials and the flaw yields full command execution, it is a severe risk to any internet-exposed management plane. The record does not detail the internal mechanism beyond the SSRF classification.
Description
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with CVSS 9.8, KEV listing with known ransomware use, and near-maximum EPSS probability make this an urgent patch-or-isolate case.
What it is
The iControl REST interface on multiple F5 BIG-IP and BIG-IQ versions exposes an unauthenticated remote command execution flaw, tracked as CWE-918 server-side request forgery. Because the interface is reachable without credentials and the flaw yields full command execution, it is a severe risk to any internet-exposed management plane. The record does not detail the internal mechanism beyond the SSRF classification.
Impact
An unauthenticated attacker can execute arbitrary commands on the affected device, gaining full control of the appliance and its traffic-handling and management functions. This can lead to configuration theft, traffic interception, and use of the device as a foothold into the internal network.
Attack surface
Reached over the network via the iControl REST interface (CVSS vector AV:N/PR:N/UI:N), so no authentication and no user interaction are required. Any deployment exposing the management interface to untrusted networks is directly reachable.
Exploitation
CISA added it to the KEV catalog on 2021-11-03 with a 2021-11-17 due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99898 (99.9th percentile), and multiple references carry the Exploit tag, indicating public exploit code exists.
What to do
- Apply the F5 vendor updates listed in advisory K03009991 for BIG-IP and BIG-IQ; upgrade to a fixed release for your branch.
- Restrict access to the iControl REST interface so it is not reachable from untrusted networks; place management access behind a management VLAN, VPN, or allowlisted jump hosts.
- Disable or block external exposure of the management interface and self-IPs where the REST service listens.
- Monitor F5 security advisories for updated guidance and re-check any end-of-software-development versions that were not evaluated.
- If immediate patching is not possible, apply network-level controls and increase monitoring of the management interface as a compensating measure.
Detection
- Hunt for unexpected or anomalous requests to the iControl REST endpoints on BIG-IP/BIG-IQ management interfaces, especially from external or non-management source IPs.
- Review appliance and web/proxy logs for command execution artifacts or unusual child processes spawned by the REST service.
- Alert on new or modified administrative accounts, tokens, or configuration changes on BIG-IP/BIG-IQ devices.
- Correlate management-interface access with threat intelligence for known exploitation of CVE-2021-22986.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-22986 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/162059/F5-iControl-Server-Side-Request-Forgery-Remote-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/162066/F5-BIG-IP-16.0.x-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://support.f5.com/csp/article/K03009991 | Vendor Advisory |
| http://packetstormsecurity.com/files/162059/F5-iControl-Server-Side-Request-Forgery-Remote-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/162066/F5-BIG-IP-16.0.x-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://support.f5.com/csp/article/K03009991 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22986 | US Government Resource |
Track CVE-2021-22986 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-22986), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.