Junglewise Threat Intelligence

CVE-2020-10221: rConfig OS Command Injection Vulnerability

CVE-2020-10221 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Executive brief

rConfig through version 3.9.4 contains an OS command injection vulnerability in lib/ajaxHandlers/ajaxAddTemplate.php. Remote authenticated attackers can execute arbitrary OS commands via shell metacharacters in the fileName POST parameter.

Affected products

  • rConfig rConfig up to and including 3.9.4

Timeline

  • 2020-03-08: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog

Related threats