CVE-2020-27464: rConfig

High severity, CVSS 7.8. EPSS: 2.5% chance of exploitation in the next 30 days.

An insecure update feature in the /updater.php component of rConfig 3.9.6 and below allows attackers to execute arbitrary code via a crafted ZIP file.

Affected products

  • rConfig rConfig: up to and including 3.9.6

Published 2021-08-20. Last modified 2026-06-17.