CVE-2024-11980: Billion Electric m100
High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.
Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device.
Affected products
- Billion Electric m100: from 1.04.1.592, before 1.04.1.592.8 (fixed in 1.04.1.592.8); from 1.04.1.613, before 1.04.613.13 (fixed in 1.04.613.13); from 1.04.1, before 1.04.1.675 (fixed in 1.04.1.675)
- Billion Electric m120n: from 1.04.1.592, before 1.04.1.592.8 (fixed in 1.04.1.592.8); from 1.04.1.613, before 1.04.613.13 (fixed in 1.04.613.13); from 1.04.1, before 1.04.1.675 (fixed in 1.04.1.675)
- Billion Electric m150: from 1.04.1.592, before 1.04.1.592.8 (fixed in 1.04.1.592.8); from 1.04.1.613, before 1.04.613.13 (fixed in 1.04.613.13); from 1.04.1, before 1.04.1.675 (fixed in 1.04.1.675)
- Billion Electric m500: from 1.04.1.592, before 1.04.1.592.8 (fixed in 1.04.1.592.8); from 1.04.1.613, before 1.04.613.13 (fixed in 1.04.613.13); from 1.04.1, before 1.04.1.675 (fixed in 1.04.1.675)
Published 2024-11-29. Last modified 2026-06-17.