CVE-2020-10221
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply updates per vendor instructions.
rConfig versions up to 3.94 contain a vulnerability where an attacker can execute arbitrary operating system commands by inserting malicious code into the fileName field when adding a template. This happens because the application doesn't properly sanitize user input before passing it to system commands.
CWE-78 OS Command Injection in lib/ajaxHandlers/ajaxAddTemplate.php allows unauthenticated remote attackers to execute arbitrary OS commands via unsanitized shell metacharacters in the fileName POST parameter. The vulnerable code directly uses user input without proper escaping or validation before command execution, enabling command chaining and arbitrary payload execution.
The full analysis of this CVE is available in Portuguese →