Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Short answer: Eclypsium reported five security issues in F5 BIG-IP Next Central Manager in May 2024. Two were assigned CVEs and were described as unauthenticated injection flaws. Three additional findings were reported without CVEs, including a manager-side API path that could create accounts on managed BIG-IP Next devices that might not appear in Central Manager. F5 disputed that those three findings were vulnerabilities because they require highly privileged access.
What product is affected?
The reporting concerns F5 BIG-IP Next Central Manager, the platform used to centrally manage BIG-IP Next instances and services. It does not establish that every F5 product, appliance or management tool is affected. The headline’s “F5 Asset Manager” wording is therefore imprecise; Central Manager is the component discussed by Eclypsium and Dark Reading.
Eclypsium disclosed the findings on May 8, 2024. Dark Reading reported F5’s response on May 9, 2024. The two CVE-assigned issues were rated 7.5, High, on the CVSS 3.1 scale, according to F5 as reported by Dark Reading. A CVSS score describes severity under the scoring model; it is not a measure of affected-customer count or proof that exploitation occurred.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchThe two CVE-assigned vulnerabilities
| Identifier | Reported mechanism | Important condition | Reported status |
|---|---|---|---|
| CVE-2024-21793 | Unauthenticated OData query-filter injection that could expose sensitive information, including administrator password hashes. | Eclypsium said the issue appears when LDAP is enabled. | Eclypsium reported that it was fixed in BIG-IP Next Central Manager 20.2.0. |
| CVE-2024-26026 | Unauthenticated SQL injection that could expose similar sensitive information. | Dark Reading reported that this flaw was not limited by the LDAP condition described for CVE-2024-21793. | Eclypsium reported that it was fixed in BIG-IP Next Central Manager 20.2.0. |
The 20.2.0 reference is a historical fix-version statement from the May 2024 disclosure. It should not be treated as the current supported release in 2026. Administrators should use the current F5 security advisory and supported-version guidance when selecting an update.
#1 Best Overall
- Quad Core J3710 Processor: F3 firewall hardware with Pentium J3710 Processor, 4 Cores 4 Threads, 2M Cache, up to 2.64 GHz, TDP 6.5 W. Compatible with OPNsense, Linux, ESXi, Proxmox
- 4 x i225V 2.5GbE LAN: J3710 mini pc with 4 x i225V 2500Mbps LAN, can monitor network data, improve network security, powerful and widely used
- DDR3 RAM mSATA Slot: J3710 firewall pc with 1 x DDR3L SO-DIMM memory, 1 x mSATA SSD slot, 1 x SATA 3.0 slot(SATA Cable included), 1 x Mini-PCIe Slot
- HD DP Dual Display: Micro firewall appliance J3710 integrated HD Graphics, HD + DP dual display interfaces improve work efficiency
- Fanless Mini Size: Firewall appliance J3710 with aluminium alloy body, fanless quiet running without noise. Size only 11 x 10 x 3.5 cm
Can attackers create hidden accounts on managed devices?
Eclypsium described a chain in which an attacker who already has access to Central Manager can use a manager-side API proxy or server-side request-forgery path to call methods on managed BIG-IP Next devices. One reported consequence was the ability to create accounts on those devices that would not be visible in Central Manager.
That claim is attributed to Eclypsium. It does not mean that an unauthenticated Internet attacker can automatically create such an account, and it does not establish that F5 independently classified this path as a vulnerability. The practical concern is persistence: a downstream-device account could remain even after Central Manager is patched or its administrator password is reset. Organizations investigating exposure should therefore check the managed devices themselves rather than treating a clean Central Manager view as proof that every device is clean.
Rank #2
- 【Processor & OS】Firewall Mini PC with Intel J3710 CPU up to 2.40GHz, 4Cores4threads 2MB L2 Cache, TDP 6w, supports AES-NI/Wol. It tested with pf-sense linux ubuntu and other popular open source os. ("DEL" key to enter BIOS)
- 【Interfaces】The firewall pc has 4 * Intel I226-V lan ports(up to 2.5G), 2 * USB3.0 ports, 1 * RS232 COM port, 2 * HD port, 1 * DC port. Equipped with VESA mount, you can install the micro pc behind the monitor to save space.
- 【RAM & Storage】The firewall router equipped with 8G DDR3 RAM, max support 8GB; 240GB mSATA SSD, can be up to 512GB. Not support HDD.
- 【Fanless Design】The small firewall box is only small but powerful. Low power consumption, only 6W; fanless heat dissipation design, aluminum alloy shell, efficient and fast heat dissipation, support 24/7 hours working, no noise. Equipped with VESA mount, you can install the micro pc behind the monitor to save space.
- 【12 Months Service】You will get 1*mini pc,size:5.27 * 4.98 * 1.43 in weigh:500g. If you encounter any problems during the use, please contact us through Amazon, we have a professional and efficient team dedicated to serving you.
The three findings without CVE numbers
- Manager-side API proxy/SSRF path: Eclypsium said the path could invoke methods on BIG-IP Next devices and create accounts that Central Manager would not display.
- Weak bcrypt cost setting: Eclypsium reported that administrator password hashes used a bcrypt cost factor of 6.
- Password-reset behavior: Eclypsium reported an authenticated administrator password-reset flow that did not require the previous password.
Eclypsium’s report did not confirm whether these three findings had been fixed at publication. F5’s position, quoted by Dark Reading, was: “Eclypsium’s findings, for which we did not issue CVEs, cannot be directly leveraged to impact the security of the product and require an attacker to first have highly privileged access. F5 does not consider these to be vulnerabilities and therefore did not issue CVEs.”
Recommended Free Tools
Eclypsium lead researcher Vlad Babkin gave the opposing assessment, saying that privileged access could still let an attacker “keep access for an indefinitely long period of time.” That is the researcher’s judgment, not an independent adjudication.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
How the two issue groups differ
| Comparison point | Two CVE-assigned issues | Three additional Eclypsium findings |
|---|---|---|
| Access prerequisite | Reported as unauthenticated injection flaws. | Require authenticated or highly privileged access, according to the vendor and reporting. |
| Technical behavior | OData query-filter injection and SQL injection. | API proxy/SSRF account creation, bcrypt cost factor 6, and a password-reset flow that did not require the old password. |
| Classification | Assigned CVE numbers and reported as 7.5 High by F5 through Dark Reading. | No CVE numbers; F5 said it did not consider them vulnerabilities. |
| Operational response | Apply the current F5 fix and supported release guidance. | Also review managed devices and strengthen management-plane access; a Central Manager update alone does not prove downstream accounts are absent. |
What administrators should do
- Identify exposure. Confirm whether your environment runs BIG-IP Next Central Manager and record its exact version and LDAP configuration.
- Follow current F5 guidance. Use F5’s presently supported advisory and release instructions. The 20.2.0 version cited in the 2024 reports is not a current-release recommendation by itself.
- Restrict the management plane. Put Central Manager and other management interfaces on an isolated network with tightly controlled administrative access. Babkin’s advice, quoted by Dark Reading, was: “First and foremost, all management interfaces should be on an isolated network.”
- Inspect managed devices. If unauthorized access is possible or suspected, review local accounts and authentication settings on each BIG-IP Next device, because an account created through the reported path might not be represented in Central Manager.
- Use incident-response procedures for suspected compromise. Preserve relevant logs, involve your security team and follow your organization’s established containment and credential-reset process. The cited reports do not provide a validated, product-specific detection checklist.
Was exploitation observed?
Eclypsium wrote on May 8, 2024: “At the time of writing, we have not seen any indication that these vulnerabilities have been exploited in the wild.” That statement describes the researchers’ visibility at disclosure time. It is not a current 2026 assessment of exploitation activity.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Bottom line on the “full takeover” claim
The evidence supports a narrower conclusion than the headline suggests. Two unauthenticated injection vulnerabilities in BIG-IP Next Central Manager were assigned CVEs and were reported fixed in version 20.2.0 in 2024. Separately, Eclypsium described three privileged-access findings, including a way to create potentially hidden accounts on managed devices; F5 rejected their vulnerability classification. Patch with current F5 guidance, isolate management interfaces and verify the devices themselves when investigating possible compromise.
Quick Recap
Best Value
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
Rank #4
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

