CVE-2025-20029 is a command injection vulnerability affecting F5 BIG-IP iControl REST and the BIG-IP TMOS Shell (tmsh) save command. According to the provided content, the flaw exists in the tmsh save command path exposed through iControl REST and may allow an authenticated attacker to execute arbitrary system commands. The issue is described by F5 as a command injection condition in tmsh, with public proof-of-concept code noted in the mention context. The affected supported BIG-IP version ranges listed in the content are 17.1.0 through 17.1.2, 16.1.0 through 16.1.5, and 15.1.0 through 15.1.10, with fixes in 17.1.2.1, 16.1.5.2, and 15.1.10.6. F5 also notes that software versions that have reached End of Technical Support were not evaluated.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides a replayable proof-of-concept (PoC) exploit for CVE-2025-20029, a command injection vulnerability in F5 BIG-IP's iControl REST API. The structure includes a Flask-based mock application (app.py) that simulates the vulnerable endpoint (/mgmt/tm/util/bash), an exploit script (exploit/exploit.py) that sends a crafted POST request to this endpoint, and supporting files for Docker-based deployment and reporting. The exploit demonstrates remote code execution by injecting commands (e.g., 'id') via a JSON payload. The environment is fully containerized for safe testing and does not interact with real F5 systems. The main attack vector is a network-based HTTP POST request to the simulated REST API endpoint. The repository is intended for educational and research purposes, providing a transparent and modifiable example of the vulnerability and its exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A command injection vulnerability in the tmsh save command in F5 BIG-IP, mentioned as part of F5's security history.
A command injection vulnerability in F5 BIG-IP tmsh for which public proof-of-concept code exists.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.