CVE-2024-11980: Billion Electric m100

High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.

Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device.

Affected products

  • Billion Electric m100: from 1.04.1.592, before 1.04.1.592.8 (fixed in 1.04.1.592.8); from 1.04.1.613, before 1.04.613.13 (fixed in 1.04.613.13); from 1.04.1, before 1.04.1.675 (fixed in 1.04.1.675)
  • Billion Electric m120n: from 1.04.1.592, before 1.04.1.592.8 (fixed in 1.04.1.592.8); from 1.04.1.613, before 1.04.613.13 (fixed in 1.04.613.13); from 1.04.1, before 1.04.1.675 (fixed in 1.04.1.675)
  • Billion Electric m150: from 1.04.1.592, before 1.04.1.592.8 (fixed in 1.04.1.592.8); from 1.04.1.613, before 1.04.613.13 (fixed in 1.04.613.13); from 1.04.1, before 1.04.1.675 (fixed in 1.04.1.675)
  • Billion Electric m500: from 1.04.1.592, before 1.04.1.592.8 (fixed in 1.04.1.592.8); from 1.04.1.613, before 1.04.613.13 (fixed in 1.04.613.13); from 1.04.1, before 1.04.1.675 (fixed in 1.04.1.675)

Published 2024-11-29. Last modified 2026-06-17.