CVE-2024-11982: Billion Electric m100
High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.
Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers with administrator privileges can access the user settings page to retrieve plaintext passwords.
Affected products
- Billion Electric m100: from 1.04.1.592, before 1.04.1.592.8 (fixed in 1.04.1.592.8); from 1.04.1.613, before 1.04.1.613.13 (fixed in 1.04.1.613.13); from 1.04.1, before 1.04.1.675 (fixed in 1.04.1.675)
- Billion Electric m120n: from 1.04.1.592, before 1.04.1.592.8 (fixed in 1.04.1.592.8); from 1.04.1.613, before 1.04.1.613.13 (fixed in 1.04.1.613.13); from 1.04.1, before 1.04.1.675 (fixed in 1.04.1.675)
- Billion Electric m150: from 1.04.1.592, before 1.04.1.592.8 (fixed in 1.04.1.592.8); from 1.04.1.613, before 1.04.1.613.13 (fixed in 1.04.1.613.13); from 1.04.1, before 1.04.1.675 (fixed in 1.04.1.675)
- Billion Electric m500: from 1.04.1.592, before 1.04.1.592.8 (fixed in 1.04.1.592.8); from 1.04.1.613, before 1.04.1.613.13 (fixed in 1.04.1.613.13); from 1.04.1, before 1.04.1.675 (fixed in 1.04.1.675)
Published 2024-11-29. Last modified 2026-06-17.