CVE-2015-10145 - CVE House
Back to Database
Status published High CVE-2015-10145

Gargoyle 1.5.x Authenticated OS Command Execution via run_commands.sh

Vulnerability Description

Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utility/run_commands.sh. The application fails to properly restrict or validate input supplied via the 'commands' parameter, allowing an authenticated attacker to execute arbitrary shell commands on the underlying system. Successful exploitation may result in full compromise of the device, including unauthorized access to system files and execution of attacker-controlled commands.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-10145

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Provensec

Affected Vendor

Affected Software

Gargoyle Router Management Utility
Vulnerable Versions:
1.5.0

Timeline

Official Publish: December 31st, 2025
Last Modified: March 23rd, 2026
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)