← Vulnerability feed

Vulnerability record · CVE-2020-13638 · published 13 November 2020

CVE-2020-13638: rConfig authentication bypass allows admin account creation

Rconfig · Rconfig

rConfig 3.9.x before 3.9.7 contains an authentication bypass in lib/crud/userprocess.php that lets an unauthenticated attacker create an administrator account. Because the flaw grants full administrative access, it exposes the configuration management system and any managed network devices to takeover. The issue is fixed in 3.9.7.

9.8 CVSS 3.1 Critical EPSS 77% · top 0.5% CWE-269 · Improper privilege management
9.8CVSS 3.1 base score, v2 7.5
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable flaw with a 9.8 CVSS score that yields full administrative control and has public exploit code.

What it is

rConfig 3.9.x before 3.9.7 contains an authentication bypass in lib/crud/userprocess.php that lets an unauthenticated attacker create an administrator account. Because the flaw grants full administrative access, it exposes the configuration management system and any managed network devices to takeover. The issue is fixed in 3.9.7.

Impact

An attacker gains a fully privileged administrator account on the rConfig instance, enabling control over device configurations and any credentials or managed systems reachable through it.

Attack surface

Reachable over the network through the user processing endpoint with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.766, 99.5th percentile) and public references are tagged Exploit, indicating exploit code is publicly available.

What to do

  • Upgrade rConfig to 3.9.7 or later immediately.
  • Restrict network access to the rConfig web interface to trusted management networks only.
  • Audit existing accounts for unauthorized administrator accounts and remove them.
  • Rotate credentials for rConfig and any managed devices it stores.
  • Monitor the user processing endpoint for unexpected account creation requests.

Detection

  • Alert on POST requests to lib/crud/userprocess.php that create or modify user accounts.
  • Review rConfig user tables and logs for new administrator accounts outside change windows.
  • Monitor for authentication bypass patterns such as requests reaching admin functions without a prior login.
  • Correlate web server logs for access to userprocess.php from untrusted source IPs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-13638 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-10221rConfig ajaxAddTemplate.php OS command injection via fileNamerConfig through 3.94 passes the fileName POST parameter in lib/ajaxHandlers/ajaxAddTemplate.php to a shell without sanitization, allowing OS command …KEVEPSS 77%analysed9.9CVE-2020-15715Rconfig vulnerabilityrConfig 3.9.5 could allow a remote authenticated attacker to execute arbitrary code on the system, because of an error in the search.crud.php script.…EPSS 4.2%9.8CVE-2020-23151Rconfig os command injection vulnerabilityrConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed d…EPSS 5.7%9.8CVE-2020-10548Rconfig sql injection vulnerabilityrConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext,…EPSS 37%9.8CVE-2020-10549Rconfig sql injection vulnerabilityrConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext…EPSS 32%9.8CVE-2020-10546rConfig unauthenticated SQL injection in compliancepolicies.inc.phprConfig 3.9.4 and earlier contains an unauthenticated SQL injection in compliancepolicies.inc.php. Because node passwords are stored in cleartext by …EPSS 87%analysed9.8CVE-2020-10547Rconfig sql injection vulnerabilityrConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are sto…EPSS 37%9.8CVE-2020-10879rConfig search.crud.php nodeId parameter OS command injectionrConfig before 3.9.5 passes the nodeId parameter from a crafted GET request directly to the exec function in lib/crud/search.crud.php without escapin…EPSS 84%analysed

Source: NIST National Vulnerability Database (record CVE-2020-13638), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.