Vulnerability record · CVE-2020-10221 · published 8 March 2020
CVE-2020-10221: rConfig ajaxAddTemplate.php OS command injection via fileName
Rconfig · Rconfig
rConfig through 3.94 passes the fileName POST parameter in lib/ajaxHandlers/ajaxAddTemplate.php to a shell without sanitization, allowing OS command injection. An attacker with a valid account can run arbitrary commands on the server, which is why this flaw was added to CISA's Known Exploited Vulnerabilities catalog.
Description
lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityRemote OS command execution with a public exploit, very high EPSS score and confirmed CISA KEV exploitation status makes this an urgent patch target.
What it is
rConfig through 3.94 passes the fileName POST parameter in lib/ajaxHandlers/ajaxAddTemplate.php to a shell without sanitization, allowing OS command injection. An attacker with a valid account can run arbitrary commands on the server, which is why this flaw was added to CISA's Known Exploited Vulnerabilities catalog.
Impact
An authenticated attacker gains arbitrary OS command execution on the rConfig host, leading to full compromise of the application server and any data or credentials it holds.
Attack surface
Reachable over the network through an HTTP POST to lib/ajaxHandlers/ajaxAddTemplate.php; the CVSS vector (PR:L) and public exploit write-ups indicate a low-privileged authenticated account is required, with no user interaction.
Exploitation
CVE-2020-10221 is listed in CISA KEV (added 2021-11-03) and has a 30-day EPSS probability of 0.802 (99.6th percentile), with public exploit references tagged Exploit; no ransomware campaign use is documented.
What to do
- Upgrade rConfig to a version later than 3.94 per vendor instructions, as required by the CISA KEV entry.
- If immediate upgrade is not possible, restrict network access to the rConfig web interface and its ajaxHandlers endpoints to trusted management networks.
- Remove or disable unused accounts and enforce least privilege so low-privileged users cannot reach template management functions.
- Validate and sanitize the fileName parameter server-side and avoid passing user input to shell commands.
- Monitor rConfig logs and host process activity for command injection attempts until patching is complete.
Detection
- Inspect web server and rConfig logs for POST requests to lib/ajaxHandlers/ajaxAddTemplate.php containing shell metacharacters (;, |, &, $(), backticks) in the fileName parameter.
- Alert on unexpected child processes spawned by the web server or PHP process, such as shells or system utilities.
- Monitor for outbound connections or file writes originating from the rConfig host that do not match normal application behavior.
- Correlate rConfig authentication events with subsequent ajaxAddTemplate.php requests from the same session or source IP.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-10221 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "rConfig OS Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/156687/rConfig-3.93-Authenticated-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://cwe.mitre.org/data/definitions/78.html | Third Party Advisory |
| https://engindemirbilek.github.io/rconfig-3.93-rce | ExploitThird Party Advisory |
| https://github.com/EnginDemirbilek/EnginDemirbilek.github.io/blob/master/rconfig-3.93-rce.html | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/156687/rConfig-3.93-Authenticated-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://cwe.mitre.org/data/definitions/78.html | Third Party Advisory |
| https://engindemirbilek.github.io/rconfig-3.93-rce | ExploitThird Party Advisory |
| https://github.com/EnginDemirbilek/EnginDemirbilek.github.io/blob/master/rconfig-3.93-rce.html | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-10221 | US Government Resource |
Track CVE-2020-10221 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-10221), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.