CVE-2020-5902 F5 BIG-IP Exploitation Attempt

A quick heads-up: we are seeing scans for F5 BIG-IP's vulnerability CVE-2020-5902.

They look like this (Host header redacted):

GET /tmui/login.jsp/..;/tmui/util/getTabSet.jsp?tabId=jaffa HTTP/1.1
User-Agent: Nuclei - Open-source project (
Accept: */*
Accept-Language: en
Connection: close
Accept-Encoding: gzip

Here is a sigma rule for CVE-2020-5902.

Didier Stevens
Senior handler
Microsoft MVP


677 Posts
ISC Handler
Jul 5th 2020
We've already seen exploitation since Friday -

Sign Up for Free or Log In to start participating in the conversation!