Gargoyle 1.5.x Authenticated OS Command Execution via run_commands.sh
Vulnerability Description
Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utility/run_commands.sh. The application fails to properly restrict or validate input supplied via the 'commands' parameter, allowing an authenticated attacker to execute arbitrary shell commands on the underlying system. Successful exploitation may result in full compromise of the device, including unauthorized access to system files and execution of attacker-controlled commands.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-10145
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Provensec
Affected Vendor
Gargoyle
View all reports →