PT-2019-4524 · Rconfig · Rconfig

Vikingfr

·

Published

2019-11-07

·

Updated

2023-01-31

·

CVE-2019-19509

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions rConfig version 3.9.3
Description The issue is related to errors in handling HTTP requests in the ajaxArchiveFiles.php component of the rConfig utility for managing network device configurations. Exploitation of this issue may allow a remote attacker to execute arbitrary commands in the target system by sending specially crafted GET requests. The path parameter is passed to the exec function without filtering, which can lead to command execution. A remote authenticated user can directly execute system commands by sending a GET request to "ajaxArchiveFiles.php".
Recommendations For rConfig version 3.9.3, consider disabling the ajaxArchiveFiles.php component or restricting access to it until a patch is available. As a temporary workaround, avoid using the path parameter in the affected "ajaxArchiveFiles.php" endpoint to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2020-00536
CVE-2019-19509

Affected Products

Rconfig