PT-2019-4524 · Rconfig · Rconfig
Vikingfr
·
Published
2019-11-07
·
Updated
2023-01-31
·
CVE-2019-19509
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
rConfig version 3.9.3
Description
The issue is related to errors in handling HTTP requests in the ajaxArchiveFiles.php component of the rConfig utility for managing network device configurations. Exploitation of this issue may allow a remote attacker to execute arbitrary commands in the target system by sending specially crafted GET requests. The
path parameter is passed to the exec function without filtering, which can lead to command execution. A remote authenticated user can directly execute system commands by sending a GET request to "ajaxArchiveFiles.php".Recommendations
For rConfig version 3.9.3, consider disabling the
ajaxArchiveFiles.php component or restricting access to it until a patch is available. As a temporary workaround, avoid using the path parameter in the affected "ajaxArchiveFiles.php" endpoint to minimize the risk of exploitation.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rconfig