EIP-2026-111691
PRE-CVErConfig 3.9.4 - 'searchField' Unauthenticated Root Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111691. PoCs published by vikingfr.
AI-analyzed exploit summary This exploit chains SQL injection (CVE-2019-19509) and command injection (CVE-2019-19585, CVE-2020-10220) in rConfig 3.9.4 to achieve unauthenticated root RCE via a reverse shell. It adds a temporary admin user, authenticates, and triggers a payload through the `ajaxArchiveFiles.php` endpoint.
Description
rConfig 3.9.4 - 'searchField' Unauthenticated Root Remote Code Execution
Exploits (1)
This exploit chains SQL injection (CVE-2019-19509) and command injection (CVE-2019-19585, CVE-2020-10220) in rConfig 3.9.4 to achieve unauthenticated root RCE via a reverse shell. It adds a temporary admin user, authenticates, and triggers a payload through the `ajaxArchiveFiles.php` endpoint.