← back
CVE-2020-12256

CVE-2020-12256

40Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 96%
exploitation probability
96%top 1% of all CVEs
observed exploitation
nono source reports it
rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbitrary JavaScript in the deviceId GET parameter to devicemgmnt.php.
Affected products
n/a · n/a