CVE-2024-11983

EUVD-2024-34040
Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into a specific SSH function and execute them on the device.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
billion_electricm100
1.04.1.592.* ≤
𝑥
< 1.04.1.592.8
ADP
billion_electricm100
1.04.1.613.* ≤
𝑥
< 1.04.1.613.13
ADP
billion_electricm100
1.04.1.* ≤
𝑥
< 1.04.1.675
ADP
billion_electricm150
1.04.1.592.* ≤
𝑥
< 1.04.1.592.8
ADP
billion_electricm150
1.04.1.613.* ≤
𝑥
< 1.04.1.613.13
ADP
billion_electricm150
1.04.1.* < ≤
𝑥
< 1.04.1.675
ADP
billion_electricm120n
1.04.1.592.* ≤
𝑥
< 1.04.1.592.8
ADP
billion_electricm120n
1.04.1.613.* ≤
𝑥
< 1.04.1.613.13
ADP
billion_electricm120n
1.04.1.* < ≤
𝑥
< 1.04.1.675
ADP
billion_electricm500
1.04.1.592.* ≤
𝑥
< 1.04.1.592.8
ADP
billion_electricm500
1.04.1.613.* ≤
𝑥
< 1.04.1.613.13
ADP
billion_electricm500
1.04.1.* < ≤
𝑥
< 1.04.1.675
ADP