Executive brief
Gargoyle is a router management utility used to administer networked devices. An authenticated attacker can execute arbitrary shell commands on affected routers via the run_commands.sh script, potentially leading to full device compromise, data theft, and unauthorized system access.
Technical details
This is an OS command injection vulnerability in the /utility/run_commands.sh script of Gargoyle router management utility versions 1.5.x. The application fails to properly validate input supplied via the 'commands' parameter, allowing an authenticated attacker to inject and execute arbitrary shell commands. The vulnerability requires prior authentication to the device. Successful exploitation grants the attacker full control over the underlying system, enabling access to sensitive files and execution of malicious commands. Patch status is not documented in available sources.
Affected products
- Gargoyle 1.5.x
Timeline
- 2025-12-31: disclosed
- 2024-06: exploited: AIRASHI botnet observed using Gargoyle vulnerability for malware distribution starting June 2024