← Vulnerability feed

Vulnerability record · CVE-2015-5453 · published 8 July 2015

CVE-2015-5453: WatchGuard XCS mailqueue.spl command injection via id parameter

Watchguard · Xcs

WatchGuard XCS 9.2 and 10.0 before build 150522 pass the id parameter of ADMIN/mailqueue.spl to a shell without sanitizing metacharacters, allowing command injection. An authenticated remote user can run arbitrary commands on the appliance, which is a security gateway sitting at the network edge.

6.5 CVSS 2.0 Medium EPSS 57% · top 1.0% CWE-77 · Command injection
6.5CVSS 2.0 base score
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id parameter to ADMIN/mailqueue.spl.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityRemote authenticated command execution on an internet-facing security appliance with public exploit code and very high EPSS, though it requires valid credentials.

What it is

WatchGuard XCS 9.2 and 10.0 before build 150522 pass the id parameter of ADMIN/mailqueue.spl to a shell without sanitizing metacharacters, allowing command injection. An authenticated remote user can run arbitrary commands on the appliance, which is a security gateway sitting at the network edge.

Impact

An attacker with valid credentials gains arbitrary command execution on the XCS appliance, enabling data theft, configuration changes, or use of the device as a pivot into the internal network.

Attack surface

Reached over the network through the administrative web interface at ADMIN/mailqueue.spl; the CVSS vector AV:N/AC:L/Au:S shows authentication is required and no user interaction is needed.

Exploitation

Not listed in CISA KEV, but EPSS is 0.573 (99th percentile) and multiple references are tagged Exploit, including Packet Storm, Exploit-DB and a Rapid7 Metasploit module, so public exploit code exists.

What to do

  • Upgrade to the WatchGuard XCS security hotfix builds referenced in the vendor release notes (9.2 and 10.0 before build 150522 are affected).
  • Restrict access to the XCS administrative interface to trusted management networks and disable it from untrusted zones.
  • Enforce strong unique credentials and least privilege for XCS admin accounts to limit who can reach the vulnerable endpoint.
  • Monitor or block requests to ADMIN/mailqueue.spl containing shell metacharacters at the web layer.
  • If patching is delayed, isolate the appliance and review logs for suspicious command execution.

Detection

  • Search web or proxy logs for requests to ADMIN/mailqueue.spl with shell metacharacters (;, |, $(), backticks) in the id parameter.
  • Alert on unexpected child processes or shell activity spawned by the XCS web service.
  • Review XCS admin authentication logs for logins from unusual source addresses preceding mailqueue.spl access.
  • Hunt for outbound connections or file changes on the appliance that do not match normal mail gateway behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-5453 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2015-5452Watchguard xcs sql injection vulnerabilitySQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitrary SQL commands via the sid …EPSS 3.4%6.8CVE-2011-2165Watchguard xcs permissions and access controls vulnerabilityThe STARTTLS implementation in WatchGuard XCS 9.0 and 9.1 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to inser…EPSS 5.2%9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed8.1CVE-2026-22719VMware Aria Operations command injection during support-assisted migrationVMware Aria Operations contains a command injection flaw (CWE-77) that an unauthenticated attacker can use to run arbitrary commands, potentially ach…KEVEPSS 18%analysed8.7CVE-2025-4008Meteobridge web interface command injection without authenticationThe Meteobridge web interface, built from CGI shell scripts and C, exposes an endpoint vulnerable to command injection. Because the endpoint also lac…KEVEPSS 94%analysed6.1CVE-2025-59689Libraesva ESG command injection via compressed email attachmentLibraesva Email Security Gateway versions 4.5 through 5.5.x before 5.5.7 are vulnerable to command injection triggered by a compressed email attachme…KEVEPSS 1.9%analysed

Source: NIST National Vulnerability Database (record CVE-2015-5453), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.