On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence85%
Public exploitation · VTP factKEV
Assessment
CVE-2021-22986 allows unauthenticated remote command execution through the BIG-IP and BIG-IQ iControl REST interface on affected versions. CISA KEV lists known exploitation and known ransomware campaign use.
Why it matters
BIG-IP and BIG-IQ commonly provide central application-delivery and management functions.
An exposed vulnerable iControl REST interface could provide an attacker with remote code execution.
Evidence
0 record references and 0 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
No CVE-specific current campaign or exploit detail is supplied.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Next watchpoint
If you use affected F5 BIG-IP or BIG-IQ versions, upgrade to F5's fixed release and restrict iControl REST access.
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
CISA KEV lists this vulnerability as known to be exploited globally.
02
EPSS is 1.00; this is predictive context, not exploitation evidence.
03
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
02
Material change ledger
What changed
KEV ADDEDCISA KEV entry added
03
Claim provenance
Evidence and source independence
1publications detected
1underlying evidence chains
0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
04
Event history
Threat timeline
00:0003 Nov
KEV ADDED
CISA KEV entry added
CISA lists global known exploitation. This is not a VTP sensor observation.
05
Original publications
Source record
SecurityWeekPRESSUNKNOWN
Thai Broadband Provider Hacked via Fortinet Vulnerability
The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools. The post Thai Broadband Provider Hacked via Fortinet Vulnerability appeared first on SecurityWeek .
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.