RULE(RULE ID:333715)

Rule General Information
Release Date: 2021-07-01
Rule Name: rConfig ajaxEditTemplate.php Remote Code Execution Vulnerability (CVE-2020-27466)
Severity:
CVE ID:
Rule Protection Details
Description: An arbitrary file write vulnerability in lib/AjaxHandlers/ajaxEditTemplate.php of rConfig 3.9.6 allows attackers to execute arbitrary code via a crafted file.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Network Device
Reference: https://ssd-disclosure.com/ssd-advisory-rconfig-unauthenticated-rce/
Solutions
Refer to the announcement or patch by the vendor: https://ssd-disclosure.com/ssd-advisory-rconfig-unauthenticated-rce/