{"id":"CVE-2021-29006","title":"rConfig 3.9.6 is affected by a Local File Disclosure vulnerability","summary":"rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-22"],"vendor":"rconfig","product":"rconfig","affected":["rconfig = 3.9.6"],"published":"2021-10-11","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-29006","references":[{"url":"https://github.com/mrojz/rconfig-exploit/blob/main/CVE-2021-29006-POC.py","label":"cve@mitre.org"},{"url":"http://rconfig.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/mrojz/rconfig-exploit/blob/main/CVE-2021-29006-POC.py","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.05603,"epssPercentile":0.92615,"ingestedAt":"2026-07-06T17:03:23.592Z","exploits":{"nuclei":["CVE-2021-29006"],"checkedAt":"2026-09-21T15:24:12.800Z"},"exploitAvailable":true,"slug":"CVE-2021-29006","body":"## Overview\n\nrConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.\n\n## Affected\n\n- `rconfig = 3.9.6`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":35.8,"likelihood":1.1,"exploitation":12,"ransomware":0},"changes":[{"seq":4517,"id":"CVE-2021-29006","ts":1788887186420,"field":"exploit_available","old":"false","new":"true"},{"seq":3400,"id":"CVE-2021-29006","ts":1788886304120,"field":"exploit_available","old":"true","new":"false"},{"seq":2255,"id":"CVE-2021-29006","ts":1788882973719,"field":"exploit_available","old":"false","new":"true"},{"seq":1284,"id":"CVE-2021-29006","ts":1788882385437,"field":"exploit_available","old":"true","new":"false"},{"seq":398,"id":"CVE-2021-29006","ts":1788881820799,"field":"exploit_available","old":"false","new":"true"}]}