CVE-2020-12256
40Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 96%
exploitation probability
96%top 1% of all CVEs
observed exploitation
nono source reports it
rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbitrary JavaScript in the deviceId GET parameter to devicemgmnt.php.
Affected products
n/a · n/a