Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device.
History

Fri, 29 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Billion Electric
Billion Electric m120n
Billion Electric m150
Billion Electric m500
CPEs cpe:2.3:a:billion_electric:m120n:*:*:*:*:*:*:*:*
cpe:2.3:a:billion_electric:m150:*:*:*:*:*:*:*:*
cpe:2.3:a:billion_electric:m500:*:*:*:*:*:*:*:*
Vendors & Products Billion Electric
Billion Electric m120n
Billion Electric m150
Billion Electric m500
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 29 Nov 2024 09:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}


Fri, 29 Nov 2024 06:30:00 +0000

Type Values Removed Values Added
Description Certain modes of in-vehicle routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device. Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device.
Title Billion Electric in-vehicle router - Missing Authentication Billion Electric router - Missing Authentication

Fri, 29 Nov 2024 06:15:00 +0000

Type Values Removed Values Added
Description Certain modes of in-vehicle routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device.
Title Billion Electric in-vehicle router - Missing Authentication
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2024-11-29T06:03:04.983Z

Updated: 2024-11-29T14:40:54.541Z

Reserved: 2024-11-29T01:52:18.057Z

Link: CVE-2024-11980

cve-icon Vulnrichment

Updated: 2024-11-29T14:40:45.800Z

cve-icon NVD

Status : Received

Published: 2024-11-29T06:15:06.747

Modified: 2024-11-29T09:15:04.197

Link: CVE-2024-11980

cve-icon Redhat

No data.