SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-19031

A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router.

HIGH 8.8EPSS 1.85%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 router series products (360 Safe Router P0,P1,P2,P3,P4), the affected version is V2.0.61.58897.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
1.85% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-77
Affected
360/safe router p0 firmware · 360/safe router p1 firmware · 360/safe router p2 firmware · 360/safe router p3 firmware · 360/safe router p4 firmware
Source
security@360.cn

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.