KEVIntel
9.8
CVSS
Critical

CVE-2019-16662

PUBLISHED

An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php...

PoC available Remote Low complexity No user interaction
Vendor
rConfig
Product
rConfig
Published
Oct 28, 2019
EPSS
94.5% · 100% pctl

Description

An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution.

php nuclei_scanner metasploit

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 10.0

AV:N/AC:L/Au:N/C:C/I:C/A:C

Exploitation status

Proof of concept available

Recorded 2019-11-10 18:26:25 UTC · Source

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) May 20, 2025

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

rconfig_install_cmd_exec

metasploit · Created Unknown

Metasploit module for CVE-2019-16662

mhaskar/CVE-2019-16662

github · Created 2019-11-10 18:26:25 UTC · 12 stars

The official exploit for rConfig 3.9.2 Pre-auth Remote Code Execution CVE-2019-16662

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Proof of Concept Exploit Available

  • Detected by Nuclei

  • Detected by Metasploit

  • Added to KEVIntel