Critical severity9.8CISA KEVNVD Advisory· Published Oct 26, 2023· Updated Jun 17, 2026
CVE-2023-46747
CVE-2023-46747
Description
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/175673/F5-BIG-IP-TMUI-AJP-Smuggling-Remote-Command-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-active-exploit-chain/nvdExploitThird Party Advisory
- my.f5.com/manage/s/article/K000137353nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
3- New SharkLoader Malware Deploys Cobalt Strike in StrikeShark CyberattacksThe Hacker News · Jun 26, 2026
- StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoaderSecurelist · Jun 24, 2026
- Top 10 web hacking techniques of 2023 - nominations openPortSwigger Research · Jan 9, 2024