Website Security & Threat Management
CVE-2020-5902: Helping to protect against the F5 TMUI RCE vulnerability

CVE-2020-5902: Helping to protect against the F5 TMUI RCE vulnerability

7/7/2020 · Michael Tremante, Maitane Zotes

What this post added

This post details the deployment of a new managed WAF rule (100315) to protect Cloudflare customers against the F5 BIG-IP TMUI RCE vulnerability (CVE-2020-5902). It explains the vulnerability, the attack patterns observed (e.g., `/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp`), and the mitigation strategy using a regular expression (`.*\.\.;.*`) to block malicious URLs. It also guides users on how to manage this rule within the Cloudflare WAF.

Read the original post ↗