CVE-2018-19031
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
04/11/2019
Last modified:
24/08/2020
Description
A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 router series products (360 Safe Router P0,P1,P2,P3,P4), the affected version is V2.0.61.58897.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:360:safe_router_p0_firmware:2.0.61.58897:*:*:*:*:*:*:* | ||
| cpe:2.3:h:360:safe_router_p0:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:360:safe_router_p1_firmware:2.0.61.58897:*:*:*:*:*:*:* | ||
| cpe:2.3:h:360:safe_router_p1:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:360:safe_router_p2_firmware:2.0.61.58897:*:*:*:*:*:*:* | ||
| cpe:2.3:h:360:safe_router_p2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:360:safe_router_p3_firmware:2.0.61.58897:*:*:*:*:*:*:* | ||
| cpe:2.3:h:360:safe_router_p3:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:360:safe_router_p4_firmware:2.0.61.58897:*:*:*:*:*:*:* | ||
| cpe:2.3:h:360:safe_router_p4:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



