CVE-2020-10549: rConfig

Critical severity, CVSS 9.8. EPSS: 32.1% chance of exploitation in the next 30 days.

rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

Affected products

  • rConfig rConfig: up to and including 3.9.4

Published 2020-06-04. Last modified 2026-06-17.