Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in through the SSH service using these credentials and obtain root privilege of the system.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-2018 Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in through the SSH service using these credentials and obtain root privilege of the system.
Fixes

Solution

For firmware version 1.04.1.592.x, please update to 1.04.1.592.10 or later. For firmware version 1.04.1.613.x, please update to 1.04.1.613.14 or later. For all other firmware version 1.04.1.x, please update to 1.04.1.676 or later.


Workaround

No workaround given by the vendor.

History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0002}

epss

{'score': 0.00022}


Tue, 11 Feb 2025 06:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Feb 2025 03:30:00 +0000

Type Values Removed Values Added
Description Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in through the SSH service using these credentials and obtain root privilege of the system.
Title Billion Electric M120N - Use of Hard-coded Credentials
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2025-02-18T18:00:30.733Z

Reserved: 2025-02-10T01:51:06.133Z

Link: CVE-2025-1143

cve-icon Vulnrichment

Updated: 2025-02-11T05:24:47.494Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-11T04:15:08.163

Modified: 2025-02-18T18:15:29.750

Link: CVE-2025-1143

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-13T11:07:24Z