CVE-2018-19031
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 router series products (360 Safe Router P0,P1,P2,P3,P4), the affected version is V2.0.61.58897.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0.61.58897 |
| Running on/with | Platform Versions |
|---|---|
360 Safe Router P0 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0.61.58897 |
| Running on/with | Platform Versions |
|---|---|
360 Safe Router P1 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0.61.58897 |
| Running on/with | Platform Versions |
|---|---|
360 Safe Router P2 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0.61.58897 |
| Running on/with | Platform Versions |
|---|---|
360 Safe Router P3 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0.61.58897 |
| Running on/with | Platform Versions |
|---|---|
360 Safe Router P4 | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.