CVE-2026-41954 PUBLISHED

iControl REST and tmsh vulnerability

Assigner: f5
Reserved: 30.04.2026 Published: 13.05.2026 Updated: 13.05.2026

Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor F5
Product BIG-IP
Versions Default: unknown
  • unaffected from 21.1.0 to * (excl.)
  • affected from 21.0.0 to 21.0.0.1 (excl.)
  • affected from 17.5.0 to 17.5.1.4 (excl.)
  • affected from 17.1.0 to 17.1.3.1 (excl.)
  • affected from 16.1.0 to * (excl.)
Vendor F5
Product BIG-IQ
Versions Default: unknown
  • affected from 8.4.0 to 8.4.1 (excl.)

Credits

  • F5 finder

References

Problem Types

  • CWE-200 Exposure of Sensitive Information to an Unauthorized Actor CWE