rConfig <= 3.9.4 - Authenticated OS Command Injection
CVE-2020-10221
Verified
Description
lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.9.4 does not properly sanitize the fileName POST parameter before using it in a shell command, allowing an authenticated attacker to inject arbitrary OS commands. This template uses default admin credentials to log in before triggering the injection; override the username / userpassword fields for environments with changed credentials.
Severity
High
CVSS Score
8.8
Exploit Probability
77%
Affected Product
rconfig
Published Date
July 14, 2026
Template Author
jayachandran from securin labs (https://securin.io)
CVE-2020-10221.yaml
8.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2020-10221
CWE ID:
cwe-78
Remediation Steps
Upgrade rConfig beyond 3.9.4 once a fixed release is available, or restrict access to /lib/ajaxHandlers/ and change default credentials.