CVE-2018-19031

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
04/11/2019
Last modified:
24/08/2020

Description

A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 router series products (360 Safe Router P0,P1,P2,P3,P4), the affected version is V2.0.61.58897.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:360:safe_router_p0_firmware:2.0.61.58897:*:*:*:*:*:*:*
cpe:2.3:h:360:safe_router_p0:-:*:*:*:*:*:*:*
cpe:2.3:o:360:safe_router_p1_firmware:2.0.61.58897:*:*:*:*:*:*:*
cpe:2.3:h:360:safe_router_p1:-:*:*:*:*:*:*:*
cpe:2.3:o:360:safe_router_p2_firmware:2.0.61.58897:*:*:*:*:*:*:*
cpe:2.3:h:360:safe_router_p2:-:*:*:*:*:*:*:*
cpe:2.3:o:360:safe_router_p3_firmware:2.0.61.58897:*:*:*:*:*:*:*
cpe:2.3:h:360:safe_router_p3:-:*:*:*:*:*:*:*
cpe:2.3:o:360:safe_router_p4_firmware:2.0.61.58897:*:*:*:*:*:*:*
cpe:2.3:h:360:safe_router_p4:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools