By adding some special fields to the uri ofrouter app function, the user could abuse background app cgi functions withoutauthentication. This affects 360 router P0 and F5C.
References
Link | Resource |
---|---|
https://security.360.cn/News/news/id/218.html | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2020-03-04 14:15
Updated : 2024-02-04 20:39
NVD link : CVE-2019-3404
Mitre link : CVE-2019-3404
CVE.ORG link : CVE-2019-3404
JSON object : View
Products Affected
360
- f5c_router
- p0_router
- f5c_router_firmware
- p0_router_firmware
CWE