Home

Description

Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED Reserved 2026-04-30 | Published 2026-05-13 | Updated 2026-05-13 | Assigner f5




MEDIUM: 4.9CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Product status

Default status
unknown

21.1.0 (custom) before *
unaffected

21.0.0 (custom) before 21.0.0.1
affected

17.5.0 (custom) before 17.5.1.4
affected

17.1.0 (custom) before 17.1.3.1
affected

16.1.0 (custom) before *
affected

Default status
unknown

8.4.0 (custom) before 8.4.1
affected

Credits

F5 finder

References

my.f5.com/manage/s/article/K32950402 vendor-advisory patch

cve.org (CVE-2026-41954)

nvd.nist.gov (CVE-2026-41954)

Download JSON