Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-34037 | Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device. |
Solution
For firmware version 1.04.1.592.x, please update to 1.04.1.592.8 or later. For firmware version 1.04.1.613.x, please update to 1.04.1.613.13 or later. For all other firmware version 1.04.1.x, please update to 1.04.1.675 or later.
Workaround
No workaround given by the vendor.
Fri, 29 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Billion Electric
Billion Electric m120n Billion Electric m150 Billion Electric m500 |
|
| CPEs | cpe:2.3:a:billion_electric:m120n:*:*:*:*:*:*:*:* cpe:2.3:a:billion_electric:m150:*:*:*:*:*:*:*:* cpe:2.3:a:billion_electric:m500:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Billion Electric
Billion Electric m120n Billion Electric m150 Billion Electric m500 |
|
| Metrics |
ssvc
|
Fri, 29 Nov 2024 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 29 Nov 2024 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Certain modes of in-vehicle routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device. | Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device. |
| Title | Billion Electric in-vehicle router - Missing Authentication | Billion Electric router - Missing Authentication |
Fri, 29 Nov 2024 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Certain modes of in-vehicle routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device. | |
| Title | Billion Electric in-vehicle router - Missing Authentication | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-11-29T14:40:54.541Z
Reserved: 2024-11-29T01:52:18.057Z
Link: CVE-2024-11980
Updated: 2024-11-29T14:40:45.800Z
Status : Received
Published: 2024-11-29T06:15:06.747
Modified: 2024-11-29T09:15:04.197
Link: CVE-2024-11980
No data.
OpenCVE Enrichment
No data.
EUVD