PT-2019-6465 · F5+1 · F5 Big-Ip Application Security Manager+1

Published

2019-05-17

·

Updated

2024-09-21

·

CVE-2019-12168

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Four-Faith Wireless Mobile Router F3x24 version 1.0 F5 BIG-IP Application Security Manager versions prior to 14.1.4.6 F5 BIG-IP Application Security Manager versions prior to 15.1.5.1
Description The issue is related to a lack of authorization in the software of Four-Faith F3x24 routers, which can allow a remote attacker to execute arbitrary code. The vulnerability can be exploited via the Command Shell screen, also known as Administration > Commands.
Recommendations For Four-Faith Wireless Mobile Router F3x24 version 1.0, consider disabling remote access to the Command Shell until a patch is available. For F5 BIG-IP Application Security Manager versions prior to 14.1.4.6, update to version 14.1.4.6 or later. For F5 BIG-IP Application Security Manager versions prior to 15.1.5.1, update to version 15.1.5.1 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-00701
CVE-2019-12168

Affected Products

F5 Big-Ip Application Security Manager
Four-Faith Wireless Mobile Router F3X24