Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Published: 2023-10-27
A critical authentication bypass vulnerability in F5’s BIG-IP could allow remote, unauthenticated attackers to execute system commands. Organizations are encouraged to apply patches as soon as possible.
https://www.securityweek.com/thai-broadband-provider-hacked-via-fortinet-vulnerability/
https://thehackernews.com/2026/06/new-sharkloader-malware-deploys-cobalt.html
https://securelist.com/strikeshark-campaign/120326/
https://thehackernews.com/2025/12/cisa-reports-prc-hackers-using.html
https://unit42.paloaltonetworks.com/nation-state-threat-actor-steals-f5-source-code/
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-242a
https://www.mandiant.com/resources/blog/initial-access-brokers-exploit-f5-screenconnect
https://www.securityweek.com/attackers-exploiting-critical-f5-big-ip-vulnerability/
https://github.com/Syedomershah99/CVE-semantic-IEEE
https://github.com/Razzlemouse/F5-BIG-IP-SmuggleShell-CVE-2023-46747-Exploit
https://github.com/zgimszhd61/CVE-2023-46747-RCE-poc
https://github.com/MacTavish2/CVE-2023-46747-Mass-RCE
https://github.com/AMELYA13/CVE-2023-46747-Mass-RCE
https://github.com/Xanexs/CVE-2023-46747-Mass-RCE
https://github.com/Rizzler4562/CVE-2023-46747-Mass-RCE
https://github.com/sanjai-AK47/CVE-2023-22527
https://github.com/sanjai-AK47/CVE-2023-22518
https://github.com/fu2x2000/CVE-2023-46747
https://github.com/W01fh4cker/CVE-2023-46747-RCE
https://github.com/bijaysenihang/CVE-2023-46747-Mass-RCE
https://github.com/k0zulzr/CVE-2023-46747-Mass-RCE
https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-active-exploit-chain/
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46747