rConfig vendor intelligence
rConfig Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting rConfig products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 5
- Known exploited vulnerabilities affecting rConfig products
- In CISA KEV
- 1
- Records also listed in the official catalog
- Beyond CISA KEV
- 4
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- rConfig KEVs with sensor-observed exploitation activity
The catalog gap matters for rConfig exposure
Four of the five exploited rConfig CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 80% of this vendor portfolio.
- 20%
- Covered by CISA
- 80%
- Beyond CISA
- 1
- Product families
Attested rConfig CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2020-10546
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored... |
rConfig | High | Beyond CISA | 17 Mar 2026 |
|
CVE-2020-13638
lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been... |
rConfig | High | Beyond CISA | 01 Jun 2025 |
|
CVE-2020-10548
rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in... |
rConfig | High | Beyond CISA | 06 Jun 2025 |
|
CVE-2019-16662
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php... |
rConfig | High | Beyond CISA | 20 May 2025 |
|
CVE-2020-10221
lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in... |
rConfig | Confirmed | In CISA | 03 Nov 2021 |
No rConfig CVEs match this search or filter.
Showing 5 of 5 rConfig known exploited vulnerabilities.
Recurring weakness patterns
Neutralization, neutralization, and privilege management account for five mapped occurrences across this rConfig KEV portfolio.
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.