Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers with administrator privileges can access the user settings page to retrieve plaintext passwords.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-34039 Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers with administrator privileges can access the user settings page to retrieve plaintext passwords.
Fixes

Solution

For firmware version 1.04.1.592.x, please update to 1.04.1.592.8 or later. For firmware version 1.04.1.613.x, please update to 1.04.1.613.13 or later. For all other firmware version 1.04.1.x, please update to 1.04.1.675 or later.


Workaround

No workaround given by the vendor.

History

Fri, 29 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Billion Electric
Billion Electric m100
Billion Electric m120n
Billion Electric m150
Billion Electric m500
CPEs cpe:2.3:a:billion_electric:m100:*:*:*:*:*:*:*:*
cpe:2.3:a:billion_electric:m120n:*:*:*:*:*:*:*:*
cpe:2.3:a:billion_electric:m150:*:*:*:*:*:*:*:*
cpe:2.3:a:billion_electric:m500:*:*:*:*:*:*:*:*
Vendors & Products Billion Electric
Billion Electric m100
Billion Electric m120n
Billion Electric m150
Billion Electric m500
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 29 Nov 2024 07:45:00 +0000

Type Values Removed Values Added
Description Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers with administrator privileges can access the user settings page to retrieve plaintext passwords.
Title Billion Electric router - Plaintext Storage of a Password
Weaknesses CWE-256
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-11-29T14:22:56.724Z

Reserved: 2024-11-29T01:52:20.686Z

Link: CVE-2024-11982

cve-icon Vulnrichment

Updated: 2024-11-29T14:22:37.889Z

cve-icon NVD

Status : Received

Published: 2024-11-29T08:15:04.580

Modified: 2024-11-29T08:15:04.580

Link: CVE-2024-11982

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.