Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rconfig

First CVE: Oct 28, 2019Active for: 7 yearsTotal CVEs: 44
92.0
VTI Score
TOP TARGET

Rconfig is a network device configuration management platform whose vulnerability profile, despite a narrow product footprint, ranks among the more prominent in its domain and skews strongly toward critical-severity outcomes. The vendor's disclosures frequently acquire public exploit code, reflecting the appeal of internet-facing management interfaces to attackers seeking device inventory compromise and lateral movement. The exposure recurs across input-handling and command-execution pathways through weakness classes including SQL injection, OS command injection, server-side request forgery, path traversal, and cross-site scripting—a pattern characteristic of web-based network administration tools with insufficient input sanitization and privilege boundaries. Defenders should treat this vendor's advisories with high priority, inventory exposed instances, and apply patches promptly given both the severity tendency and the public-exploit availability for this product. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
44
Total CVEs
More Total CVEs than 98% of tracked vendors
8.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
2.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Rconfig over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 28, 2019
6 years ago
Most Recent CVE
Aug 1, 2023
1,088 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (44 CVEs).

44 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-16662CRITICAL
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is
Oct 28, 20199.894NOYES
CVE-2020-10220CRITICAL
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.
Mar 7, 20209.892NOYES
CVE-2020-10221HIGH
lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter.
Mar 8, 20208.885YESYES
CVE-2019-19509HIGH
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFiles.php because the path paramet
Jan 6, 20208.883NOYES
CVE-2020-10546CRITICAL
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability
Jun 4, 20209.880NOYES
CVE-2020-12256MEDIUM
rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbitrary JavaScript in the deviceI
May 18, 20205.479NOYES
CVE-2020-10879CRITICAL
rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed directly to the exec function withou
Mar 23, 20209.879NOYES
CVE-2020-13638CRITICAL
lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7.
Nov 13, 20209.876NOYES
CVE-2020-12259MEDIUM
rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript
May 18, 20205.476NOYES
CVE-2019-16663HIGH
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to
Oct 28, 20198.874NONO
View all 44 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products44 CVEs
18%
55%
27%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (6.8%)
Network41 (93.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low44 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None38 (86.4%)
Unknown0 (0.0%)
Required6 (13.6%)
Privileges Required
Low25 (56.8%)
High0 (0.0%)
None19 (43.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (44 CVEs).

CISA KEV
1 CVE
2.3% of CVEs· 99th percentile
Metasploit
4 CVEs
9.1% of CVEs· 98th percentile
Nuclei
14 CVEs
31.8% of CVEs· 98th percentile
ExploitDB
6 CVEs
13.6% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rconfig.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rconfig — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rconfig's Products

View all 1 CNAs →

Top CWEs