CVE-2018-19031 describes a command injection vulnerability in 360 router series products (P0, P1, P2, P3, P4) running firmware version V2.0.61.58897. An authenticated attacker can exploit this by passing crafted parameters to a background process, leading to a CVSSv3.1 score of 8.8 (High). This allows for complete compromise of confidentiality, integrity, and availability. Despite its high severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.61.58897CPE matchmatch criteria | cpe:2.3:o:360:safe_router_p0_firmware:2.0.61.58897:*:*:*:*:*:*:* | ||
2.0.61.58897CPE matchmatch criteria | cpe:2.3:o:360:safe_router_p1_firmware:2.0.61.58897:*:*:*:*:*:*:* | ||
2.0.61.58897CPE matchmatch criteria | cpe:2.3:o:360:safe_router_p2_firmware:2.0.61.58897:*:*:*:*:*:*:* | ||
2.0.61.58897CPE matchmatch criteria | cpe:2.3:o:360:safe_router_p3_firmware:2.0.61.58897:*:*:*:*:*:*:* | ||
2.0.61.58897CPE matchmatch criteria | cpe:2.3:o:360:safe_router_p4_firmware:2.0.61.58897:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.