PT-2024-8937 · Billion Electric · Billion Electric Routers
Chiao-Lin Yu
+1
·
Published
2024-11-29
·
Updated
2024-12-04
·
CVE-2024-11982
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Billion Electric routers (affected versions not specified)
Description:
The issue concerns a plaintext storage of password vulnerability. Remote attackers with administrator privileges can access the user settings page to retrieve passwords in plaintext. This could allow an unauthorized party to gain access to protected information.
Recommendations:
For all affected versions, consider restricting access to the user settings page until a fix is available.
As a temporary workaround, avoid using the
password variable in the affected API endpoint until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Billion Electric Routers