CVE-2015-5453: WatchGuard Xcs

Medium severity, CVSS 6.5. EPSS: 58.7% chance of exploitation in the next 30 days.

Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id parameter to ADMIN/mailqueue.spl.

Affected products

  • WatchGuard Xcs: version 9.2 only; version 10.0 only

Published 2015-07-08. Last modified 2026-06-17.