CVE-2024-11983: Billion Electric m100

High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.

Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into a specific SSH function and execute them on the device.

Affected products

  • Billion Electric m100: from 1.04.1.592, before 1.04.1.592.8 (fixed in 1.04.1.592.8); from 1.04.1.613, before 1.04.1.613.13 (fixed in 1.04.1.613.13); from 1.04.1, before 1.04.1.675 (fixed in 1.04.1.675)
  • Billion Electric m120n: from 1.04.1.592, before 1.04.1.592.8 (fixed in 1.04.1.592.8); from 1.04.1.613, before 1.04.1.613.13 (fixed in 1.04.1.613.13); from 1.04.1, before 1.04.1.675 (fixed in 1.04.1.675)
  • Billion Electric m150: from 1.04.1.592, before 1.04.1.592.8 (fixed in 1.04.1.592.8); from 1.04.1.613, before 1.04.1.613.13 (fixed in 1.04.1.613.13); from 1.04.1, before 1.04.1.675 (fixed in 1.04.1.675)
  • Billion Electric m500: from 1.04.1.592, before 1.04.1.592.8 (fixed in 1.04.1.592.8); from 1.04.1.613, before 1.04.1.613.13 (fixed in 1.04.1.613.13); from 1.04.1, before 1.04.1.675 (fixed in 1.04.1.675)

Published 2024-11-29. Last modified 2026-06-17.