If you have your rcon pass in server.cfg, likely getting/viewing that file.
Don't store it there.
If you just MUST have an rcon password/access, use command line options to start server.
There are also several workshop addons with exploits by various people.
I don't know them, only have seen various reports here in our forum.