Vulnerability record · CVE-2015-5453 · published 8 July 2015
CVE-2015-5453: WatchGuard XCS mailqueue.spl command injection via id parameter
Watchguard · Xcs
WatchGuard XCS 9.2 and 10.0 before build 150522 pass the id parameter of ADMIN/mailqueue.spl to a shell without sanitizing metacharacters, allowing command injection. An authenticated remote user can run arbitrary commands on the appliance, which is a security gateway sitting at the network edge.
Description
Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id parameter to ADMIN/mailqueue.spl.
AV:N/AC:L/Au:S/C:P/I:P/A:P
Automated analysis
high priorityRemote authenticated command execution on an internet-facing security appliance with public exploit code and very high EPSS, though it requires valid credentials.
What it is
WatchGuard XCS 9.2 and 10.0 before build 150522 pass the id parameter of ADMIN/mailqueue.spl to a shell without sanitizing metacharacters, allowing command injection. An authenticated remote user can run arbitrary commands on the appliance, which is a security gateway sitting at the network edge.
Impact
An attacker with valid credentials gains arbitrary command execution on the XCS appliance, enabling data theft, configuration changes, or use of the device as a pivot into the internal network.
Attack surface
Reached over the network through the administrative web interface at ADMIN/mailqueue.spl; the CVSS vector AV:N/AC:L/Au:S shows authentication is required and no user interaction is needed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.573 (99th percentile) and multiple references are tagged Exploit, including Packet Storm, Exploit-DB and a Rapid7 Metasploit module, so public exploit code exists.
What to do
- Upgrade to the WatchGuard XCS security hotfix builds referenced in the vendor release notes (9.2 and 10.0 before build 150522 are affected).
- Restrict access to the XCS administrative interface to trusted management networks and disable it from untrusted zones.
- Enforce strong unique credentials and least privilege for XCS admin accounts to limit who can reach the vulnerable endpoint.
- Monitor or block requests to ADMIN/mailqueue.spl containing shell metacharacters at the web layer.
- If patching is delayed, isolate the appliance and review logs for suspicious command execution.
Detection
- Search web or proxy logs for requests to ADMIN/mailqueue.spl with shell metacharacters (;, |, $(), backticks) in the id parameter.
- Alert on unexpected child processes or shell activity spawned by the XCS web service.
- Review XCS admin authentication logs for logins from unusual source addresses preceding mailqueue.spl access.
- Hunt for outbound connections or file changes on the appliance that do not match normal mail gateway behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-5453 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-5453), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.