CVE-2025-1143: Billion Electric m100

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in through the SSH service using these credentials and obtain root privilege of the system.

Affected products

  • Billion Electric m100: from 1.04.1.159, before 1.04.1.592.10 (fixed in 1.04.1.592.10); from 1.04.1.613, before 1.04.1.613.14 (fixed in 1.04.1.613.14); from 1.04.1, before 1.04.1.676 (fixed in 1.04.1.676)
  • Billion Electric m120n: from 1.04.1.592, before 1.04.1.592.10 (fixed in 1.04.1.592.10); from 1.04.1.613, before 1.04.1.613.14 (fixed in 1.04.1.613.14); from 1.04.1, before 1.04.1.676 (fixed in 1.04.1.676)
  • Billion Electric m150: from 1.04.1.592, before 1.04.1.592.10 (fixed in 1.04.1.592.10); from 1.04.1.613, before 1.04.1.613.14 (fixed in 1.04.1.613.14); from 1.04.1, before 1.04.1.676 (fixed in 1.04.1.676)
  • Billion Electric m500: from 1.04.1.592, before 1.04.1.592.10 (fixed in 1.04.1.592.10); from 1.04.1.613, before 1.04.1.613.14 (fixed in 1.04.1.613.14); from 1.04.1, before 1.04.1.676 (fixed in 1.04.1.676)

Published 2025-02-11. Last modified 2026-06-17.