CVE-2010-4566

Citrix Access Gateway <5.0 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2010-4566. PoCs published by Metasploit, George D. Gal, George D. Gal, Erwin Paternotte, including Metasploit module exploits/unix/webapp/citrix_access_gateway_exec.

AI-analyzed exploit summary This exploit leverages a command injection vulnerability in Citrix Access Gateway's NTLM authentication module by embedding shell metacharacters in the login form, allowing arbitrary command execution. The PoC uses a POST request to trigger the vulnerability and includes a check method to verify exploitability.

Description

The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/16916

This exploit leverages a command injection vulnerability in Citrix Access Gateway's NTLM authentication module by embedding shell metacharacters in the login form, allowing arbitrary command execution. The PoC uses a POST request to trigger the vulnerability and includes a check method to verify exploitability.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Citrix Access Gateway with ntlm_authenticator module
No auth needed
Prerequisites: Network access to the Citrix Access Gateway · NTLM authentication enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by George D. Gal · textremotelinux
https://www.exploit-db.com/exploits/15806

This advisory details a command injection vulnerability in Citrix Access Gateway's legacy NT4 authentication module, where shell metacharacters in the password field can lead to arbitrary command execution. The vulnerability arises from improper handling of user credentials passed to the Samba 'samedit' utility.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Citrix Access Gateway (Enterprise Edition up to 9.2-49.8, Standard & Advanced Edition prior to 5.0)
No auth needed
Prerequisites: Access to the Citrix Access Gateway authentication interface · Legacy NT4 authentication enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by George D. Gal, Erwin Paternotte · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/citrix_access_gateway_exec.rb

This Metasploit module exploits a command injection vulnerability in Citrix Access Gateway's NTLM authentication by injecting shell metacharacters into the login form, allowing arbitrary command execution. The exploit leverages the Samba 'samedit' utility to achieve RCE.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Citrix Access Gateway with ntlm_authenticator
No auth needed
Prerequisites: Network access to Citrix Access Gateway · NTLM authentication enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1024893
Vendor Advisory x_refsource_confirm
http://support.citrix.com/article/CTX127613
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8119
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/70099
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/16916

Scores

EPSS 0.7185
EPSS Percentile 98.8%

Details

Status published
Products (13)
citrix/access_gateway .8.0 m50.3
citrix/access_gateway 8.0 m48.7 (3 CPE variants)
citrix/access_gateway 8.1-69.4
citrix/access_gateway 9.0.71.3
citrix/access_gateway 9.1-104.5
citrix/access_gateway 4.5 (4 CPE variants)
citrix/access_gateway 4.5.5
citrix/access_gateway 4.5.6
citrix/access_gateway 4.5.7
citrix/access_gateway 4.6.1
... and 3 more
Published Jan 14, 2011
Tracked Since Feb 18, 2026