某未公开的 BIG-IP 配置实用程序页面存在一个漏洞,可能允许攻击者伪造错误消息。 影响: 攻击者可以诱使已认证的 BIG-IP 用户访问恶意链接,从而在受害者的 BIG-IP 配置实用程序 Web 浏览器会话中反射出一条被伪造的错误消息。这是一个控制平面问题,数据平面不受影响。 注意: 已达到技术支持结束(EoTS)的软件版本未进行评估。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66842 | 8.8 HIGH | BIG-IP and BIG-IQ Configuration utility vulnerability |
| CVE-2026-77180 | 8.3 HIGH | NGINX Ingress Controller vulnerability |
| CVE-2026-18329 | 8.2 HIGH | NGINX ngx_http_js_module vulnerability |
| CVE-2026-78689 | 8.1 HIGH | NGINX ngx_http_js_module vulnerablility |
| CVE-2026-66362 | 8.1 HIGH | NGF vulnerability |
| CVE-2026-78222 | 7.5 HIGH | NGINX ngx_http_js_module vulnerability |
No comments yet