S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-9425 Scanner

Detects 'Information Disclosure' vulnerability in rConfig affects v. before 3.9.4.

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-9425
7.5
CVSS

An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved cleartext credentials via a GET request to settings.php. Because the application was not exiting after a redirect is applied, the rest of the page still executed, resulting in the disclosure of cleartext credentials in the response.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

rConfig is a network configuration management tool that allows IT professionals to manage and organize network devices such as routers, switches, and firewalls. It facilitates the automation of network configuration backups and changes, and enables documentation of network changes.

The CVE-2020-9425 vulnerability that was discovered in rConfig before version 3.9.4 poses a significant security threat to enterprise networks that use this software. An unauthenticated attacker can retrieve saved cleartext credentials through a GET request to settings.php. The application does not exit after a redirect is applied, resulting in the disclosure of cleartext credentials in the response.

This vulnerability can lead to the theft of sensitive information that can be used to launch targeted cyber attacks on the network. If an attacker gains access to network devices by using stolen credentials, they can interfere with network traffic, steal confidential data, or plant malware. Additionally, a compromised network device can be used to pivot to other network segments and devices, leading to a more extensive compromise.

With the pro features of the s4e.io platform, users can quickly and easily detect vulnerabilities in their digital assets. By using the platform, users can scan their networks for security vulnerabilities, get customized remediation recommendations, and receive alerts for any new vulnerabilities that may arise. Take advantage of s4e.io to keep your digital assets safe from cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of rConfig are advised to take the following precautions:

  • Upgrade to the latest version of the software (version 3.9.4) that contains a fix for this vulnerability.
  • Restrict access to the settings.php file and other sensitive information by using access controls and firewalls. 
  • Use strong, unique passwords for all network devices and applications.
  • Implement multi-factor authentication to prevent unauthorized access to network devices.
  • Monitor network activity for signs of suspicious behavior and take appropriate action.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-9425 scanner - Information Disclosure vulnerability in rConfig | S4E