← Vulnerability feed

Vulnerability record · CVE-2020-10221 · published 8 March 2020

CVE-2020-10221: rConfig ajaxAddTemplate.php OS command injection via fileName

Rconfig · Rconfig

rConfig through 3.94 passes the fileName POST parameter in lib/ajaxHandlers/ajaxAddTemplate.php to a shell without sanitization, allowing OS command injection. An attacker with a valid account can run arbitrary commands on the server, which is why this flaw was added to CISA's Known Exploited Vulnerabilities catalog.

8.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 77% · top 0.5% CWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 9.0
77%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
9References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityRemote OS command execution with a public exploit, very high EPSS score and confirmed CISA KEV exploitation status makes this an urgent patch target.

What it is

rConfig through 3.94 passes the fileName POST parameter in lib/ajaxHandlers/ajaxAddTemplate.php to a shell without sanitization, allowing OS command injection. An attacker with a valid account can run arbitrary commands on the server, which is why this flaw was added to CISA's Known Exploited Vulnerabilities catalog.

Impact

An authenticated attacker gains arbitrary OS command execution on the rConfig host, leading to full compromise of the application server and any data or credentials it holds.

Attack surface

Reachable over the network through an HTTP POST to lib/ajaxHandlers/ajaxAddTemplate.php; the CVSS vector (PR:L) and public exploit write-ups indicate a low-privileged authenticated account is required, with no user interaction.

Exploitation

CVE-2020-10221 is listed in CISA KEV (added 2021-11-03) and has a 30-day EPSS probability of 0.802 (99.6th percentile), with public exploit references tagged Exploit; no ransomware campaign use is documented.

What to do

  • Upgrade rConfig to a version later than 3.94 per vendor instructions, as required by the CISA KEV entry.
  • If immediate upgrade is not possible, restrict network access to the rConfig web interface and its ajaxHandlers endpoints to trusted management networks.
  • Remove or disable unused accounts and enforce least privilege so low-privileged users cannot reach template management functions.
  • Validate and sanitize the fileName parameter server-side and avoid passing user input to shell commands.
  • Monitor rConfig logs and host process activity for command injection attempts until patching is complete.

Detection

  • Inspect web server and rConfig logs for POST requests to lib/ajaxHandlers/ajaxAddTemplate.php containing shell metacharacters (;, |, &, $(), backticks) in the fileName parameter.
  • Alert on unexpected child processes spawned by the web server or PHP process, such as shells or system utilities.
  • Monitor for outbound connections or file writes originating from the rConfig host that do not match normal application behavior.
  • Correlate rConfig authentication events with subsequent ajaxAddTemplate.php requests from the same session or source IP.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-10221 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "rConfig OS Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-10221 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2020-15715Rconfig vulnerabilityrConfig 3.9.5 could allow a remote authenticated attacker to execute arbitrary code on the system, because of an error in the search.crud.php script.…EPSS 4.2%9.8CVE-2020-23151Rconfig os command injection vulnerabilityrConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed d…EPSS 5.7%9.8CVE-2020-13638rConfig authentication bypass allows admin account creationrConfig 3.9.x before 3.9.7 contains an authentication bypass in lib/crud/userprocess.php that lets an unauthenticated attacker create an administrato…EPSS 77%analysed9.8CVE-2020-10548Rconfig sql injection vulnerabilityrConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext,…EPSS 37%9.8CVE-2020-10549Rconfig sql injection vulnerabilityrConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext…EPSS 32%9.8CVE-2020-10546rConfig unauthenticated SQL injection in compliancepolicies.inc.phprConfig 3.9.4 and earlier contains an unauthenticated SQL injection in compliancepolicies.inc.php. Because node passwords are stored in cleartext by …EPSS 87%analysed9.8CVE-2020-10547Rconfig sql injection vulnerabilityrConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are sto…EPSS 37%9.8CVE-2020-10879rConfig search.crud.php nodeId parameter OS command injectionrConfig before 3.9.5 passes the nodeId parameter from a crafted GET request directly to the exec function in lib/crud/search.crud.php without escapin…EPSS 84%analysed

Source: NIST National Vulnerability Database (record CVE-2020-10221), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.