F5 BIG-IP version 16.0.x suffers from an iControl REST remote code execution vulnerability.
b4ef0983df32e4af9b07348e405a0b8acc9a16e40982e9ca0b30305f3759ae05
This Metasploit module exploits a pre-authentication server-side request forgery vulnerability in the F5 iControl REST API's /mgmt/shared/authn/login endpoint to generate an X-F5-Auth-Token that can be used to execute root commands on an affected BIG-IP or BIG-IQ device.
af88cb0e39f85d5705c7b101b5d8123cacf7ab8455f5fc35d14ea16b6fc75d0d