← Vulnerability feed

Vulnerability record · CVE-2020-10546 · published 4 June 2020

CVE-2020-10546: rConfig unauthenticated SQL injection in compliancepolicies.inc.php

Rconfig · Rconfig

rConfig 3.9.4 and earlier contains an unauthenticated SQL injection in compliancepolicies.inc.php. Because node passwords are stored in cleartext by default, the flaw can expose credentials for monitored network devices. This makes a single web-facing injection a path to broader network compromise.

9.8 CVSS 3.1 Critical EPSS 87% · top 0.2% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network SQL injection with a 9.8 CVSS score, public exploit code, and very high EPSS, compounded by cleartext credential storage enabling lateral movement.

What it is

rConfig 3.9.4 and earlier contains an unauthenticated SQL injection in compliancepolicies.inc.php. Because node passwords are stored in cleartext by default, the flaw can expose credentials for monitored network devices. This makes a single web-facing injection a path to broader network compromise.

Impact

An attacker can read and modify database contents, including cleartext device credentials, and use them to move laterally to monitored network devices. This can lead to full compromise of managed infrastructure.

Attack surface

Reachable over the network via HTTP against the vulnerable compliancepolicies.inc.php endpoint. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Public exploit code is referenced in third-party advisories, and EPSS is 0.8733 (99.7th percentile), indicating high likelihood of exploitation. It is not listed in CISA KEV.

What to do

  • Upgrade rConfig to a version later than 3.9.4 if available; if no fixed release exists, isolate or decommission the instance.
  • Restrict network access to the rConfig web interface to trusted management networks only.
  • Stop storing device passwords in cleartext; rotate all credentials that may have been exposed.
  • Deploy a WAF rule to block SQL injection patterns against compliancepolicies.inc.php.
  • Monitor and audit rConfig database and device access for signs of lateral movement.

Detection

  • Inspect web server logs for requests to compliancepolicies.inc.php containing SQL metacharacters or UNION/boolean patterns.
  • Alert on unexpected outbound connections from the rConfig host to managed network devices.
  • Review database query logs for anomalous SELECT statements against credential or node tables.
  • Monitor for use of known public exploit scripts against the rConfig endpoint.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-10546 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-10221rConfig ajaxAddTemplate.php OS command injection via fileNamerConfig through 3.94 passes the fileName POST parameter in lib/ajaxHandlers/ajaxAddTemplate.php to a shell without sanitization, allowing OS command …KEVEPSS 77%analysed9.9CVE-2020-15715Rconfig vulnerabilityrConfig 3.9.5 could allow a remote authenticated attacker to execute arbitrary code on the system, because of an error in the search.crud.php script.…EPSS 4.2%9.8CVE-2020-23151Rconfig os command injection vulnerabilityrConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed d…EPSS 5.7%9.8CVE-2020-13638rConfig authentication bypass allows admin account creationrConfig 3.9.x before 3.9.7 contains an authentication bypass in lib/crud/userprocess.php that lets an unauthenticated attacker create an administrato…EPSS 77%analysed9.8CVE-2020-10548Rconfig sql injection vulnerabilityrConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext,…EPSS 37%9.8CVE-2020-10549Rconfig sql injection vulnerabilityrConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext…EPSS 32%9.8CVE-2020-10547Rconfig sql injection vulnerabilityrConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are sto…EPSS 37%9.8CVE-2020-10879rConfig search.crud.php nodeId parameter OS command injectionrConfig before 3.9.5 passes the nodeId parameter from a crafted GET request directly to the exec function in lib/crud/search.crud.php without escapin…EPSS 84%analysed

Source: NIST National Vulnerability Database (record CVE-2020-10546), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.