Rconfig is a network device configuration management platform whose vulnerability profile, despite a narrow product footprint, ranks among the more prominent in its domain and skews strongly toward critical-severity outcomes. The vendor's disclosures frequently acquire public exploit code, reflecting the appeal of internet-facing management interfaces to attackers seeking device inventory compromise and lateral movement. The exposure recurs across input-handling and command-execution pathways through weakness classes including SQL injection, OS command injection, server-side request forgery, path traversal, and cross-site scripting—a pattern characteristic of web-based network administration tools with insufficient input sanitization and privilege boundaries. Defenders should treat this vendor's advisories with high priority, inventory exposed instances, and apply patches promptly given both the severity tendency and the public-exploit availability for this product. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rconfig over time
Signals from CVEs in this vendor scope (44 CVEs).
44 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16662CRITICAL An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is | Oct 28, 2019 | 9.8 | 94 | NO | YES |
CVE-2020-10220CRITICAL An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter. | Mar 7, 2020 | 9.8 | 92 | NO | YES |
CVE-2020-10221HIGH lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter. | Mar 8, 2020 | 8.8 | 85 | YES | YES |
CVE-2019-19509HIGH An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFiles.php because the path paramet | Jan 6, 2020 | 8.8 | 83 | NO | YES |
CVE-2020-10546CRITICAL rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability | Jun 4, 2020 | 9.8 | 80 | NO | YES |
CVE-2020-12256MEDIUM rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbitrary JavaScript in the deviceI | May 18, 2020 | 5.4 | 79 | NO | YES |
CVE-2020-10879CRITICAL rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed directly to the exec function withou | Mar 23, 2020 | 9.8 | 79 | NO | YES |
CVE-2020-13638CRITICAL lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7. | Nov 13, 2020 | 9.8 | 76 | NO | YES |
CVE-2020-12259MEDIUM rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript | May 18, 2020 | 5.4 | 76 | NO | YES |
CVE-2019-16663HIGH An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to | Oct 28, 2019 | 8.8 | 74 | NO | NO |
Signals from CVEs in this vendor scope (44 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rconfig.
Media articles that mention a CVE ID that affects a product developed by Rconfig — matched by CVE ID, not by vendor name.