By adding some special fields to the uri ofrouter app function, the user could abuse background app cgi functions withoutauthentication. This affects 360 router P0 and F5C.
References
Link | Resource |
---|---|
https://security.360.cn/News/news/id/218.html | Vendor Advisory |
https://security.360.cn/News/news/id/218.html | Vendor Advisory |
Configurations
History
21 Nov 2024, 04:42
Type | Values Removed | Values Added |
---|---|---|
References | () https://security.360.cn/News/news/id/218.html - Vendor Advisory |
Information
Published : 2020-03-04 14:15
Updated : 2024-11-21 04:42
NVD link : CVE-2019-3404
Mitre link : CVE-2019-3404
CVE.ORG link : CVE-2019-3404
JSON object : View
Products Affected
360
- f5c_router_firmware
- f5c_router
- p0_router_firmware
- p0_router
CWE