CVE-2024-11980

EUVD-2024-34037
Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
billion_electricm150
1.04.1.592.* ≤
𝑥
< 1.04.1.592.8
ADP
billion_electricm150
1.04.1.613.* ≤
𝑥
< 1.04.613.13
ADP
billion_electricm150
1.04.1.* < ≤
𝑥
< 1.04.1.675
ADP
billion_electricm150
1.04.1.592.* ≤
𝑥
< 1.04.1.592.8
ADP
billion_electricm150
1.04.1.613.* ≤
𝑥
< 1.04.613.13
ADP
billion_electricm150
1.04.1.* < ≤
𝑥
< 1.04.1.675
ADP
billion_electricm120n
1.04.1.592.* ≤
𝑥
< 1.04.1.592.8
ADP
billion_electricm120n
1.04.1.613.* ≤
𝑥
< 1.04.613.13
ADP
billion_electricm120n
1.04.1.* < ≤
𝑥
< 1.04.1.675
ADP
billion_electricm500
1.04.1.592.* ≤
𝑥
< 1.04.1.592.8
ADP
billion_electricm500
1.04.1.613.* ≤
𝑥
< 1.04.613.13
ADP
billion_electricm500
1.04.1.* < ≤
𝑥
< 1.04.1.675
ADP