← All CVEs NewScan detects
criticalKEV

CVE-2022-1388

F5 BIG-IP iControl REST authentication bypass -> RCE

Severity
critical
Affected product
F5 BIG-IP
Affected versions
F5 BIG-IP < 16.1.2.2
Fixed in
F5 BIG-IP 16.1.2.2
CISA KEV
Listed as a known exploited vulnerability
EPSS
96% chance of exploitation in the next 30 days
Added to NewScan
2026-07-13
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the F5 BIG-IP appliance and reports this CVE when the detected version falls inside the affected range below.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →