CVE 4.9 MEDIUM

iControl REST and tmsh vulnerability_CVE-2026-41954

4.9 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Description

Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information.Β Β Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Basic Information

ID CVE-2026-41954
Source f5
Published May 13, 2026 at 14:12

Affected Product

Vendor F5
Product BIG-IP
Version 21.1.0
Affected Versions F5 BIG-IP 21.0.0
F5 BIG-IP 17.5.0
F5 BIG-IP 17.1.0
F5 BIG-IP 16.1.0
F5 BIG-IQ 8.4.0

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.