Vulnerability record · CVE-2020-12256 · published 18 May 2020
CVE-2020-12256: rConfig devicemgmnt.php reflected XSS via deviceId parameter
Rconfig · Rconfig
rConfig 3.9.4 fails to properly validate user input in devicemgmnt.php, allowing reflected cross-site scripting through the deviceId GET parameter. An attacker who can get a victim to open a crafted link can run arbitrary JavaScript in the victim's browser session. Because the affected page is part of the device management interface, script execution occurs in the context of an authenticated user.
Description
rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbitrary JavaScript in the deviceId GET parameter to devicemgmnt.php.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityThe flaw is a reflected XSS requiring authentication and user interaction with limited direct impact, but public exploit code and a very high EPSS score raise the practical risk.
What it is
rConfig 3.9.4 fails to properly validate user input in devicemgmnt.php, allowing reflected cross-site scripting through the deviceId GET parameter. An attacker who can get a victim to open a crafted link can run arbitrary JavaScript in the victim's browser session. Because the affected page is part of the device management interface, script execution occurs in the context of an authenticated user.
Impact
An attacker can execute arbitrary JavaScript in a victim's browser, enabling session theft, credential capture, or actions performed as the logged-in rConfig user. The scope change in the CVSS vector means the script can affect resources beyond the vulnerable component.
Attack surface
Reached over the network via a crafted URL to devicemgmnt.php with a malicious deviceId GET parameter. The CVSS vector requires low privileges (PR:L) and user interaction (UI:R), so the attacker needs a valid low-privileged account and must convince a victim to click the link.
Exploitation
Not listed in CISA KEV and no ransomware use documented, but EPSS is very high at 0.95752 (99.87th percentile) and both references are tagged Exploit, indicating public exploit code exists.
What to do
- Upgrade rConfig to a version later than 3.9.4 that fixes the devicemgmnt.php input handling; if no fixed release is available, apply vendor guidance.
- Encode or reject untrusted input in the deviceId parameter and apply context-aware output encoding on devicemgmnt.php.
- Deploy a content security policy that blocks inline and untrusted script execution on the rConfig interface.
- Restrict access to the rConfig management interface to trusted networks or VPN and enforce least privilege on accounts.
- Train users not to open unsolicited links to the rConfig application.
Detection
- Search web and proxy logs for requests to devicemgmnt.php with script-like or encoded payloads in the deviceId parameter.
- Alert on reflected input containing script tags, event handlers, or JavaScript URIs in HTTP responses from rConfig.
- Monitor for anomalous authenticated sessions or actions following visits to crafted devicemgmnt.php URLs.
- Review rConfig access logs for unusual referrers or repeated requests to devicemgmnt.php from a single source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://gist.github.com/farid007/8855031bad0e497264e4879efb5bc9f8 | ExploitThird Party Advisory |
| https://gist.github.com/farid007/8855031bad0e497264e4879efb5bc9f8 | ExploitThird Party Advisory |
Track CVE-2020-12256 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-12256), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.