Vulnerability record · CVE-2020-10546 · published 4 June 2020
CVE-2020-10546: rConfig unauthenticated SQL injection in compliancepolicies.inc.php
Rconfig · Rconfig
rConfig 3.9.4 and earlier contains an unauthenticated SQL injection in compliancepolicies.inc.php. Because node passwords are stored in cleartext by default, the flaw can expose credentials for monitored network devices. This makes a single web-facing injection a path to broader network compromise.
Description
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network SQL injection with a 9.8 CVSS score, public exploit code, and very high EPSS, compounded by cleartext credential storage enabling lateral movement.
What it is
rConfig 3.9.4 and earlier contains an unauthenticated SQL injection in compliancepolicies.inc.php. Because node passwords are stored in cleartext by default, the flaw can expose credentials for monitored network devices. This makes a single web-facing injection a path to broader network compromise.
Impact
An attacker can read and modify database contents, including cleartext device credentials, and use them to move laterally to monitored network devices. This can lead to full compromise of managed infrastructure.
Attack surface
Reachable over the network via HTTP against the vulnerable compliancepolicies.inc.php endpoint. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Public exploit code is referenced in third-party advisories, and EPSS is 0.8733 (99.7th percentile), indicating high likelihood of exploitation. It is not listed in CISA KEV.
What to do
- Upgrade rConfig to a version later than 3.9.4 if available; if no fixed release exists, isolate or decommission the instance.
- Restrict network access to the rConfig web interface to trusted management networks only.
- Stop storing device passwords in cleartext; rotate all credentials that may have been exposed.
- Deploy a WAF rule to block SQL injection patterns against compliancepolicies.inc.php.
- Monitor and audit rConfig database and device access for signs of lateral movement.
Detection
- Inspect web server logs for requests to compliancepolicies.inc.php containing SQL metacharacters or UNION/boolean patterns.
- Alert on unexpected outbound connections from the rConfig host to managed network devices.
- Review database query logs for anomalous SELECT statements against credential or node tables.
- Monitor for use of known public exploit scripts against the rConfig endpoint.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/theguly/exploits/blob/master/CVE-2020-10546.py | ExploitThird Party Advisory |
| https://theguly.github.io/2020/09/rconfig-3.9.4-multiple-vulnerabilities/ | ExploitThird Party Advisory |
| https://github.com/theguly/exploits/blob/master/CVE-2020-10546.py | ExploitThird Party Advisory |
| https://theguly.github.io/2020/09/rconfig-3.9.4-multiple-vulnerabilities/ | ExploitThird Party Advisory |
Track CVE-2020-10546 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-10546), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.