VYPR

rConfig

by rConfig

CVEs (48)

  • CVE-2026-77914MedAug 24, 2026
    risk 0.42cvss 6.5epss

    rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated users to read arbitrary files by supplying crafted filenames containing directory traversal sequences to the export download endpoint. Attackers can manipulate the filename parameter with…

  • CVE-2023-24366MedMar 27, 2023
    risk 0.42cvss 6.5epss 0.01

    An arbitrary file download vulnerability in rConfig v6.8.0 allows attackers to download sensitive files via a crafted HTTP request.

  • CVE-2020-25353MedAug 20, 2021
    risk 0.42cvss 6.5epss 0.01

    A server-side request forgery (SSRF) vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability allowed remote authenticated attackers to open a connection to the machine via the deviceIpAddr and connPort parameters.

  • CVE-2020-25351MedAug 20, 2021
    risk 0.42cvss 6.5epss 0.01

    An information disclosure vulnerability in rConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed remote authenticated attackers to read files on the system via a crafted request sent to to the /lib/crud/configcompare.crud.php script.

  • CVE-2026-64826MedAug 12, 2026
    risk 0.35cvss 6.5epss 0.00

    rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized directory traversal sequences in the filename GET parameter of the download_export() method. Attackers can craft requests with ../…

  • CVE-2026-63102MedJul 20, 2026
    risk 0.35cvss 5.4epss 0.00

    rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. Attackers can exploit the…

  • CVE-2020-25352MedAug 20, 2021
    risk 0.35cvss 5.4epss 0.02

    A stored cross-site scripting (XSS) vulnerability in the /devices.php function inrConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed remote attackers to perform arbitrary Javascript execution through entering a crafted payload into the 'Model' field then…

  • CVE-2020-15712MedJul 28, 2020
    risk 0.28cvss 4.3epss 0.02

    rConfig 3.9.5 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a crafted request to the ajaxGetFileByPath.php script containing hexadecimal encoded "dot dot" sequences (%2f..%2f) in the path parameter to view arbitrary…

Page 3 of 3