Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into a specific SSH function and execute them on the device.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-34040 Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into a specific SSH function and execute them on the device.
Fixes

Solution

For firmware version 1.04.1.592.x, please update to 1.04.1.592.8 or later. For firmware version 1.04.1.613.x, please update to 1.04.1.613.13 or later. For all other firmware version 1.04.1.x, please update to 1.04.1.675 or later.


Workaround

No workaround given by the vendor.

History

Fri, 29 Nov 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Billion Electric
Billion Electric m100
Billion Electric m120n
Billion Electric m150
Billion Electric m500
CPEs cpe:2.3:a:billion_electric:m100:*:*:*:*:*:*:*:*
cpe:2.3:a:billion_electric:m120n:*:*:*:*:*:*:*:*
cpe:2.3:a:billion_electric:m150:*:*:*:*:*:*:*:*
cpe:2.3:a:billion_electric:m500:*:*:*:*:*:*:*:*
Vendors & Products Billion Electric
Billion Electric m100
Billion Electric m120n
Billion Electric m150
Billion Electric m500
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 29 Nov 2024 07:45:00 +0000

Type Values Removed Values Added
Description Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into a specific SSH function and execute them on the device.
Title Billion Electric router - OS Command Injection
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-11-29T14:10:39.561Z

Reserved: 2024-11-29T01:52:22.084Z

Link: CVE-2024-11983

cve-icon Vulnrichment

Updated: 2024-11-29T14:09:28.088Z

cve-icon NVD

Status : Received

Published: 2024-11-29T08:15:04.733

Modified: 2024-11-29T08:15:04.733

Link: CVE-2024-11983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.