PT-2024-8935 · Billion · Billion M150+3

Chiao-Lin Yu

+1

·

Published

2024-11-29

·

Updated

2024-12-04

·

CVE-2024-11981

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Billion M100 versions (affected versions not specified) Billion M150 versions (affected versions not specified) Billion M120N versions (affected versions not specified) Billion M500 versions (affected versions not specified)
Description: The issue is related to an authentication bypass vulnerability in certain models of Billion Electric routers. This vulnerability allows unauthenticated attackers to retrieve contents of arbitrary web pages, effectively bypassing security restrictions and gaining unauthorized access to protected information. The vulnerability can be exploited remotely.
Recommendations: For Billion M100, update to a version that fixes the authentication bypass issue. For Billion M150, update to a version that fixes the authentication bypass issue. For Billion M120N, update to a version that fixes the authentication bypass issue. For Billion M500, update to a version that fixes the authentication bypass issue. As a temporary workaround, consider restricting access to sensitive web pages until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10610
CVE-2024-11981

Affected Products

Billion M100
Billion M120N
Billion M150
Billion M500