PatchSiren

PatchSiren cyber security CVE debrief

CVE-2019-16662 Unknown Vendor CVE debrief

CVE-2019-16662 describes a direct command-execution issue in rConfig 3.9.2. The supplied description says an attacker can send a GET request to ajaxServerSettingsChk.php and reach the exec function through the rootUname parameter without filtering. That makes this a high-priority issue for any exposed or in-use affected instance.

Vendor
Unknown Vendor
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2019-10-28
Original CVE updated
2026-06-14
Advisory published
2026-06-14
Advisory updated
2026-06-14

Who should care

Administrators and security teams responsible for rConfig 3.9.2 deployments, especially systems reachable over the network or used to manage infrastructure.

Technical summary

The provided CVE description states that ajaxServerSettingsChk.php passes the rootUname parameter to exec without filtering. Because the request is sent over GET, the vulnerable path is network-reachable if the endpoint is accessible. The EPSS signal provided with this record is very high (0.94461, 99.994th percentile), which increases operational concern, though it is only a probability signal and not proof of exploitation.

Defensive priority

High. The issue is described as direct system command execution, and the supplied EPSS signal indicates a strong likelihood of exploitation interest. Treat exposed instances as urgent to assess.

Recommended defensive actions

  • Identify whether rConfig 3.9.2 is deployed anywhere in your environment.
  • Restrict or block access to the affected endpoint if exposure cannot be eliminated immediately.
  • Apply the vendor's fixed version or other official remediation if available from authoritative sources.
  • Review web and system logs for requests to ajaxServerSettingsChk.php and other signs of unexpected command execution.
  • If the system was exposed, validate host integrity and investigate for unauthorized changes or persistence.

Evidence notes

This debrief is based on the supplied CVE description, which explicitly names rConfig 3.9.2, ajaxServerSettingsChk.php, the rootUname parameter, and unchecked use of exec. Risk context is further supported by the supplied EPSS record from FIRST showing a score of 0.94461 and percentile 0.99994. Official CVE and NVD links are included as reference points; no additional facts were inferred beyond the provided corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2019-16662 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2019-16662

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2019-16662 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2019-16662

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.first.org/epss/

    first_epss

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.