rConfig Vulnerabilities and Affected Products
Vulnerabilities associated with rConfig.
Products
Clear product- rConfig7 vulnerabilities
- rConfig v8 Core1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-64826HIGH | rConfig < 8.2.13 Path Traversal File Read via FileDownloadControllerrConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized directory traversal sequences in the filename GET parameter of the download_export() method. Attackers can craft requests with ../ sequences to escape the exports base directory and access sensitive files readable by the web server process, including application environment files containing encryption keys, database credentials, and mail configuration… CWE-22Aug 12, 2026 | CVSS7.1v4.0 | EPSS0.373% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-13638CRITICAL | rConfig rConfig Improper Privilege Managementlib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7. | CVSS9.8v3.1 | EPSS76.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2020-10546CRITICAL | rConfig rConfig Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices. | CVSS9.8v3.1 | EPSS87.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2020-10548CRITICAL | rConfig rConfig Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices. | CVSS9.8v3.1 | EPSS37.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2020-10221HIGH | rConfig OS Command Injection Vulnerabilitylib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter. CWE-78Mar 8, 2020 | CVSS8.8v3.1 | EPSS36.8% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-19509HIGH | rConfig rConfig Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFiles.php because the path parameter is passed to the exec function without filtering, which can lead to command execution. CWE-78Jan 6, 2020 | CVSS8.8v3.1 | EPSS71.6% | PoCs3 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-16662CRITICAL | rConfig rConfig Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution. | CVSS9.8v3.1 | EPSS97.7% | PoCs4 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |