BIG-IP 存在一个漏洞,任何角色的经过认证的用户都可能通过向流量管理用户界面(TMUI)发送一个未公开的请求来创建管理员账户。 影响: 该漏洞可能允许一个已认证且能够访问 BIG-IP 管理接口的攻击者,通过在 BIG-IP 系统上创建管理员账户来提升权限。此漏洞仅涉及控制平面,不涉及数据平面。 备注: 已达到技术支持终止期(End of Technical Support, EoTS)的软件版本未纳入评估范围。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77180 | 8.3 HIGH | NGINX Ingress Controller vulnerability |
| CVE-2026-18329 | 8.2 HIGH | NGINX ngx_http_js_module vulnerability |
| CVE-2026-78689 | 8.1 HIGH | NGINX ngx_http_js_module vulnerablility |
| CVE-2026-66362 | 8.1 HIGH | NGF vulnerability |
| CVE-2026-78222 | 7.5 HIGH | NGINX ngx_http_js_module vulnerability |
| CVE-2026-63020 | 3.1 LOW | BIG-IP Configuration utility vulnerability |
No comments yet