CVE-2025-1143: Billion Electric m100
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in through the SSH service using these credentials and obtain root privilege of the system.
Affected products
- Billion Electric m100: from 1.04.1.159, before 1.04.1.592.10 (fixed in 1.04.1.592.10); from 1.04.1.613, before 1.04.1.613.14 (fixed in 1.04.1.613.14); from 1.04.1, before 1.04.1.676 (fixed in 1.04.1.676)
- Billion Electric m120n: from 1.04.1.592, before 1.04.1.592.10 (fixed in 1.04.1.592.10); from 1.04.1.613, before 1.04.1.613.14 (fixed in 1.04.1.613.14); from 1.04.1, before 1.04.1.676 (fixed in 1.04.1.676)
- Billion Electric m150: from 1.04.1.592, before 1.04.1.592.10 (fixed in 1.04.1.592.10); from 1.04.1.613, before 1.04.1.613.14 (fixed in 1.04.1.613.14); from 1.04.1, before 1.04.1.676 (fixed in 1.04.1.676)
- Billion Electric m500: from 1.04.1.592, before 1.04.1.592.10 (fixed in 1.04.1.592.10); from 1.04.1.613, before 1.04.1.613.14 (fixed in 1.04.1.613.14); from 1.04.1, before 1.04.1.676 (fixed in 1.04.1.676)
Published 2025-02-11. Last modified 2026-06-17.