CVE-2018-19031
A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 router series products (360 Safe Router P0,P1,P2,P3,P4), the affected version is V2.0.61.58897.
Published:Nov 4, 2019
Last Modified:Nov 21, 2024
EPS:Nov 4, 2019
EPSS Score:0.03819
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
360
Product
Safe Router P0
360
Safe Router P0
Vendor
360
Product
Safe Router P0 Firmware
360
Safe Router P0 Firmware
Vendor
360
Product
Safe Router P1
360
Safe Router P1
Vendor
360
Product
Safe Router P1 Firmware
360
Safe Router P1 Firmware
Vendor
360
Product
Safe Router P2
360
Safe Router P2
Vendor
360
Product
Safe Router P2 Firmware
360
Safe Router P2 Firmware
Vendor
360
Product
Safe Router P3
360
Safe Router P3
Vendor
360
Product
Safe Router P3 Firmware
360
Safe Router P3 Firmware
Vendor
360
Product
Safe Router P4
360
Safe Router P4
Vendor
360
Product
Safe Router P4 Firmware
360
Safe Router P4 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
