CVE-2022-41622 is a cross-site request forgery vulnerability affecting all evaluated versions of F5 BIG-IP and BIG-IQ through the iControl SOAP management interface. The flaw allows a remote attacker to induce an authenticated user of the management interface to submit unintended requests to the affected device. Because the issue resides in iControl SOAP, exploitation targets administrative actions exposed through that interface and can cause the device to process attacker-chosen requests within the victim user's authenticated session.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting CVE-2022-41622, a CSRF vulnerability in the F5 BIG-IP iControl SOAP API. The exploit leverages a browser-based attack: it starts a malicious HTTP server and waits for an authenticated F5 administrator to visit the attacker's page. When visited, the page automatically submits a crafted SOAP request to the F5 device, exploiting the CSRF flaw to write an arbitrary file to the device as root. The module supports three targets: writing to a file that executes on reboot, writing a backdoor script that executes on user login, or writing to a custom file (if permitted by SELinux). The default payload is a Python Meterpreter reverse shell, but any unix command payload can be used. The exploit is weaponized, as it is part of the Metasploit framework and allows for flexible payload selection. The main attack vectors are browser-based CSRF and network access to the F5 management interface. The module defines several fingerprintable endpoints, including the SOAP API URI, specific file paths on the target, and example URLs used in the payload. The repository is well-structured, containing only the exploit module file, and is intended for use within the Metasploit framework.
This repository is a comprehensive proof-of-concept exploit for CVE-2022-41622, a CSRF vulnerability in the F5 BIG-IP SOAP management interface. The exploit allows an attacker to perform privileged actions (such as creating admin users or uploading files) by tricking an authenticated admin into visiting a malicious page (CSRF) or by directly sending SOAP requests if credentials are known. The repository includes: - A Ruby script (f5-soap-exploit.rb) that can send crafted SOAP XML payloads to the vulnerable endpoint, either directly (with credentials) or by generating CSRF HTML forms for browser-based attacks. - Multiple HTML files in the csrf/ and examples/ directories that serve as ready-to-use CSRF payloads for adding users or backdoors. - XML templates for various SOAP actions (add user, upload file, move file, etc.). - Example shell scripts and payloads for achieving code execution (e.g., replacing /var/run/config/timeout.sh to spawn a reverse shell). - A large set of WSDL files documenting the full SOAP API surface of F5 BIG-IP, useful for crafting additional payloads. The exploit is operational and weaponized, providing both direct and indirect (CSRF) attack vectors. It targets the /iControl/iControlPortal.cgi endpoint over HTTPS and manipulates files such as /var/run/config/timeout.sh for persistence or code execution. The repository is well-documented and includes all necessary payloads and templates for exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.