A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 router series products (360 Safe Router P0,P1,P2,P3,P4), the affected version is V2.0.61.58897.
                
            References
                    | Link | Resource | 
|---|---|
| https://security.360.cn/News/news/id/188.html | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
Configuration 2 (hide)
| AND | 
 
 | 
Configuration 3 (hide)
| AND | 
 
 | 
Configuration 4 (hide)
| AND | 
 
 | 
Configuration 5 (hide)
| AND | 
 
 | 
History
                    No history.
Information
                Published : 2019-11-04 15:15
Updated : 2020-08-24 17:37
NVD link : CVE-2018-19031
Mitre link : CVE-2018-19031
CVE.ORG link : CVE-2018-19031
JSON object : View
Products Affected
                360
- safe_router_p4
- safe_router_p3
- safe_router_p1
- safe_router_p3_firmware
- safe_router_p1_firmware
- safe_router_p2_firmware
- safe_router_p4_firmware
- safe_router_p2
- safe_router_p0
- safe_router_p0_firmware
CWE
                
                    
                        
                        CWE-77
                        
            Improper Neutralization of Special Elements used in a Command ('Command Injection')
