By adding some special fields to the uri ofrouter app function, the user could abuse background app cgi functions withoutauthentication. This affects 360 router P0 and F5C.
References
Link | Resource |
---|---|
https://security.360.cn/News/news/id/218.html | Vendor Advisory |
Information
Published : 2020-03-04 06:15
Updated : 2020-08-24 10:37
NVD link : CVE-2019-3404
Mitre link : CVE-2019-3404
JSON object : View
CWE
Products Affected
360
- f5c_router
- f5c_router_firmware
- p0_router_firmware
- p0_router