Vulnerability record · CVE-2020-10879 · published 23 March 2020
CVE-2020-10879: rConfig search.crud.php nodeId parameter OS command injection
Rconfig · Rconfig
rConfig before 3.9.5 passes the nodeId parameter from a crafted GET request directly to the exec function in lib/crud/search.crud.php without escaping it. This allows an unauthenticated remote attacker to execute arbitrary operating system commands on the server. Because rConfig is a network configuration management tool, compromise can expose managed device credentials and infrastructure.
Description
rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed directly to the exec function without being escaped.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, a public exploit, and very high EPSS make this an urgent remote code execution risk.
What it is
rConfig before 3.9.5 passes the nodeId parameter from a crafted GET request directly to the exec function in lib/crud/search.crud.php without escaping it. This allows an unauthenticated remote attacker to execute arbitrary operating system commands on the server. Because rConfig is a network configuration management tool, compromise can expose managed device credentials and infrastructure.
Impact
An attacker can run arbitrary commands with the privileges of the web server process, leading to full server compromise, data theft, and potential lateral movement into managed network devices.
Attack surface
Reachable over the network via a crafted GET request to lib/crud/search.crud.php; the CVSS vector indicates no authentication and no user interaction are required.
Exploitation
A public Exploit-DB entry exists, and EPSS is very high (0.83862, 99.677th percentile), indicating likely active exploitation; CISA KEV does not list it.
What to do
- Upgrade rConfig to 3.9.5 or later, which contains the patch commit 3385f906427d228c48b914625136bf620f4ca0a9.
- If immediate upgrade is not possible, restrict network access to the rConfig web interface to trusted management networks only.
- Deploy a WAF rule to block requests to lib/crud/search.crud.php containing shell metacharacters in the nodeId parameter.
- Run the rConfig web service under a low-privilege account with no unnecessary OS command execution rights.
- Audit the server for signs of compromise and rotate any credentials stored or managed by rConfig.
Detection
- Monitor web server logs for GET requests to lib/crud/search.crud.php with suspicious nodeId values containing shell metacharacters such as ;, |, $(), or backticks.
- Alert on unexpected child processes spawned by the web server user (for example, sh, bash, curl, wget, nc).
- Review outbound network connections from the rConfig host to unusual destinations.
- Check for unauthorized files or scheduled tasks created on the rConfig server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/rconfig/rconfig/commit/3385f906427d228c48b914625136bf620f4ca0a9 | Patch |
| https://www.exploit-db.com/exploits/48241 | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/rconfig/rconfig/commit/3385f906427d228c48b914625136bf620f4ca0a9 | Patch |
| https://www.exploit-db.com/exploits/48241 | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2020-10879 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-10879), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.