Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into a specific SSH function and execute them on the device.
History

Fri, 29 Nov 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Billion Electric
Billion Electric m100
Billion Electric m120n
Billion Electric m150
Billion Electric m500
CPEs cpe:2.3:a:billion_electric:m100:*:*:*:*:*:*:*:*
cpe:2.3:a:billion_electric:m120n:*:*:*:*:*:*:*:*
cpe:2.3:a:billion_electric:m150:*:*:*:*:*:*:*:*
cpe:2.3:a:billion_electric:m500:*:*:*:*:*:*:*:*
Vendors & Products Billion Electric
Billion Electric m100
Billion Electric m120n
Billion Electric m150
Billion Electric m500
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 29 Nov 2024 07:45:00 +0000

Type Values Removed Values Added
Description Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into a specific SSH function and execute them on the device.
Title Billion Electric router - OS Command Injection
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2024-11-29T06:57:24.047Z

Updated: 2024-11-29T14:10:39.561Z

Reserved: 2024-11-29T01:52:22.084Z

Link: CVE-2024-11983

cve-icon Vulnrichment

Updated: 2024-11-29T14:09:28.088Z

cve-icon NVD

Status : Received

Published: 2024-11-29T08:15:04.733

Modified: 2024-11-29T08:15:04.733

Link: CVE-2024-11983

cve-icon Redhat

No data.