PT-2024-8936 · Billion · Billion M150+4

Chiao-Lin Yu

+1

·

Published

2024-11-29

·

Updated

2024-12-04

·

CVE-2024-11980

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions: Billion Electric routers (affected versions not specified) Billion M100 (affected versions not specified) Billion M150 (affected versions not specified) Billion M120N (affected versions not specified) Billion M500 (affected versions not specified)
Description: The issue concerns a Missing Authentication vulnerability in certain modes of Billion Electric routers. This vulnerability allows unauthenticated remote attackers to directly access specific functionality, obtaining partial device information, modifying the WiFi SSID, and restarting the device. The vulnerability is related to the absence of authentication for a critical function, which can be exploited by remote attackers to bypass security restrictions, gain unauthorized access to protected information, or cause a denial of service.
Recommendations: For Billion Electric routers, upgrade the firmware immediately to mitigate the risk. For Billion M100, upgrade the firmware to the latest version. For Billion M150, upgrade the firmware to the latest version. For Billion M120N, upgrade the firmware to the latest version. For Billion M500, upgrade the firmware to the latest version. As a temporary workaround, consider restricting access to the vulnerable functionality until a patch is available. Avoid using the vulnerable routers until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10610
BDU:2024-10611
BDU:2024-10612
CVE-2024-11980

Affected Products

Billion Electric Routers
Billion M100
Billion M120N
Billion M150
Billion M500