VulnerabilityModified
CVE-2018-19031
A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router.
HIGH 8.8EPSS 1.85%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 router series products (360 Safe Router P0,P1,P2,P3,P4), the affected version is V2.0.61.58897.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.85% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- 360/safe router p0 firmware · 360/safe router p1 firmware · 360/safe router p2 firmware · 360/safe router p3 firmware · 360/safe router p4 firmware
- Source
- security@360.cn
References
- https://security.360.cn/News/news/id/188.htmlVendor Advisory
- https://security.360.cn/News/news/id/188.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.