CVE-2018-19031

A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 router series products (360 Safe Router P0,P1,P2,P3,P4), the affected version is V2.0.61.58897.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
360STCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
VendorProductVersion
360safe_router_p0_firmware
2.0.61.58897
360safe_router_p1_firmware
2.0.61.58897
360safe_router_p2_firmware
2.0.61.58897
360safe_router_p3_firmware
2.0.61.58897
360safe_router_p4_firmware
2.0.61.58897
𝑥
= Vulnerable software versions