CVE-2020-5950: F5 BIG-IP Advanced Firewall Manager

Medium severity, CVSS 5.3. EPSS: 1% chance of exploitation in the next 30 days.

On BIG-IP 14.1.0-14.1.2.6, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user is granted the admin role.

Affected products

  • F5 BIG-IP Advanced Firewall Manager: from 14.1.0, before 14.1.2.7 (fixed in 14.1.2.7)

Published 2020-12-11. Last modified 2026-06-17.