CVE-2019-18866: Blaauwproducts Remote Kiln Control

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allows a user to extract arbitrary data from the rkc database.

Affected products

  • Blaauwproducts Remote Kiln Control: version 3.0.0 only; up to and including 3.0.0

Published 2020-05-07. Last modified 2026-06-17.