← Back

Rconfig

rconfig

Vendor: Rconfig • 44 CVEs

CVEs (44)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rconfig
1Rconfig
Jun 17, 2026
Nov 28, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A downloadFile.php download_file path traversal vulnerability in rConfig through 3.9.3 allows attackers to list files in arbitrary folders and potentially download files. NOTE: the discoverer later reported that there wa...Show more
A downloadFile.php download_file path traversal vulnerability in rConfig through 3.9.3 allows attackers to list files in arbitrary folders and potentially download files. NOTE: the discoverer later reported that there was not a "fully working exploit.Show less
1Rconfig
1Rconfig
Jun 17, 2026
Nov 21, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
rConfig 3.9.2 allows devices.php?searchColumn= SQL injection.
1Rconfig
1Rconfig
Jun 17, 2026
Oct 28, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function without filtering, wh...Show more
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function without filtering, which can lead to command execution.Show less
1Rconfig
1Rconfig
Jun 17, 2026
Oct 28, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filt...Show more
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution.Show less