F5 disclosed a critical flaw in the BIG-IP iControl REST interface, tracked as CVE-2022-1388, that allows attackers to bypass authentication and achieve unauthenticated remote code execution on exposed administrative interfaces. The issue affects the interaction between Apache and the iControl REST service, where crafted requests abusing headers such as X-F5-Auth-Token and Connection can reach privileged command-execution functionality without valid credentials. The vulnerability carries a CVSS 9.8 rating and impacts multiple BIG-IP versions, prompting F5 to publish patches and mitigation guidance.
Technical analysis showed the bug stems from request-handling logic that lets specially formed traffic evade normal authentication checks and invoke sensitive endpoints. Security reporting also indicated the flaw was being actively exploited in the wild, with thousands of potentially vulnerable internet-exposed BIG-IP systems observed, increasing the risk to organizations using the platform for application delivery and security services. Defenders were urged to patch affected devices quickly or apply F5’s recommended mitigations to restrict exposure of the management interface.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Reporting cited Palo Alto's observation that attackers were actively exploiting CVE-2022-1388 in the wild against internet-exposed BIG-IP administrative interfaces. The same reporting noted that more than 2,500 potentially vulnerable BIG-IP instances were visible via Censys.
Technical analysis explained that the flaw stems from how BIG-IP's Apache front end and iControl REST backend process the X-F5-Auth-Token and Connection headers. By causing the proxy to strip the token after an initial presence check, an attacker can bypass authentication and reach a command-execution endpoint.
F5 published advisory K23605346 for CVE-2022-1388, a critical authentication bypass in the BIG-IP iControl REST interface that can lead to unauthenticated remote code execution. The advisory lists patched versions including 17.0.0, 16.1.2.2, 15.1.5.1, 14.1.4.6, and 13.1.5, and provides mitigation guidance for customers that cannot upgrade immediately.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.