References https://nvd.nist.gov/vuln/detail/CVE-2019-16663 https://www.cve.org/CVERecord?id=CVE-2019-16663 https://shells.systems/rconfig-v3-9-2-authenticated-and-unauthenticated-rce-cve-2019-16663-and-cve-2019-16662/ https://zsecurity.org/how-i-discovered-a-remote-code-execution-in-rconfig-v3-9-2-cve-2019-16663-cve-2019-16662/ https://www.exploit-db.com/exploits/47555 https://github.com/mhaskar/CVE-2019-16663 https://gbhackers.com/rconfig-rce/ https://thehackernews.com/2019/11/rConfig-network-vulnerability.html https://www.cvedetails.com/version/619835/Rconfig-Rconfig-3.9.2.html https://pentest-tools.com/vulnerabilities-exploits/rconfig-393-multiple-rce-vulnerabilities-version-check_4124
Related VulnerabilitiesPoCnacos-v3-auth-scope-bypass: Nacos 3.x - Unauthenticated Admin TakeoverPoCCVE-2020-10221: rConfig <= 3.9.4 - Authenticated OS Command InjectionCloudreve网盘 /api/v3/share/search 未授权访问漏洞WordPress TI WooCommerce Wishlist /wp-json/wc/v3/wishlist/get_products SQL 注入漏洞(CVE-2024-43917)PoCCVE-2026-33476: SiYuan <= v3.6.1 - Path TraversalRancher /v3-public/localProviders/local 默认口令漏洞Owncast /api/admin/serverconfig 默认口令漏洞PoCCVE-2026-31807: SiYuan <= v3.5.9 - SVG Animate Element XSSPoCCVE-2026-31809: SiYuan <= v3.5.9 - Cross Site ScriptingPoCCVE-2026-34453: SiYuan <= v3.6.1 - Bookmark Data DisclosurePoCCVE-2025-54068: Laravel Livewire v3 - Remote Command Execution(CVE-2023-53885)Webutler v3.2 PHAR文件远程代码执行漏洞NodeBB /api/v3/search/categories SQL 注入漏洞(CVE-2025-50979)