Vulnerability record · CVE-2019-16663 · published 28 October 2019
CVE-2019-16663: rConfig search.crud.php catCommand OS command injection
Rconfig · Rconfig
rConfig 3.9.2 passes the catCommand parameter from search.crud.php directly to the exec function without filtering, allowing OS command injection. An attacker who can reach that endpoint can run arbitrary system commands on the server, which is severe for a network configuration management tool that often holds device credentials.
Description
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function without filtering, which can lead to command execution.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote command execution with a high CVSS score and very high EPSS probability, though exploitation requires some level of authentication.
What it is
rConfig 3.9.2 passes the catCommand parameter from search.crud.php directly to the exec function without filtering, allowing OS command injection. An attacker who can reach that endpoint can run arbitrary system commands on the server, which is severe for a network configuration management tool that often holds device credentials.
Impact
An attacker gains arbitrary command execution with the privileges of the web server process, enabling data theft, credential access, and further lateral movement or host compromise.
Attack surface
Reached over the network via a GET request to search.crud.php with a crafted catCommand parameter. The CVSS vector indicates low privileges are required (PR:L), so some form of authenticated access is needed; no user interaction is required.
Exploitation
Public exploit code and technical descriptions are referenced, and EPSS is very high (0.847, 99.7th percentile), indicating elevated likelihood of exploitation. CVE-2019-16663 is not listed in CISA KEV, and no ransomware group usage is documented.
What to do
- Upgrade rConfig to a version later than 3.9.2 that fixes the command injection; check the vendor download page for the current release.
- If immediate upgrade is not possible, restrict network access to the rConfig web interface to trusted management networks only.
- Validate and sanitize the catCommand parameter server-side and avoid passing user input to exec or shell functions.
- Run the rConfig web service with least privilege and isolate it from sensitive credentials and internal networks.
- Monitor and rotate any device credentials or secrets stored in rConfig in case of prior compromise.
Detection
- Inspect web server and application logs for GET requests to search.crud.php with suspicious catCommand values containing shell metacharacters.
- Alert on child processes spawned by the web server user (for example sh, bash, curl, wget, nc) that are unexpected for normal rConfig operation.
- Monitor outbound network connections from the rConfig host to unusual destinations that could indicate command-and-control or data exfiltration.
- Review file integrity and new files or scripts written in web-accessible directories on the rConfig server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://drive.google.com/open?id=1XmR2MSMb3cKARFk3XxmPkwz6GhAP1JxL | ExploitThird Party Advisory |
| https://drive.google.com/open?id=1kQGmboKfwob4RwlMjnv6ER2Za1GUptOi | ExploitThird Party Advisory |
| https://gist.github.com/mhaskar/e7e454c7cb0dd9a139b0a43691e258a0 | ExploitThird Party Advisory |
| https://rconfig.com/download | Product |
| https://shells.systems/rconfig-v3-9-2-authenticated-and-unauthenticated-rce-cve-2019-16663-and-cve-2019-16662/ | ExploitTechnical DescriptionThird Party Advisory |
| https://drive.google.com/open?id=1XmR2MSMb3cKARFk3XxmPkwz6GhAP1JxL | ExploitThird Party Advisory |
| https://drive.google.com/open?id=1kQGmboKfwob4RwlMjnv6ER2Za1GUptOi | ExploitThird Party Advisory |
| https://gist.github.com/mhaskar/e7e454c7cb0dd9a139b0a43691e258a0 | ExploitThird Party Advisory |
| https://rconfig.com/download | Product |
| https://shells.systems/rconfig-v3-9-2-authenticated-and-unauthenticated-rce-cve-2019-16663-and-cve-2019-16662/ | ExploitTechnical DescriptionThird Party Advisory |
Track CVE-2019-16663 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-16663), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.