Billion Electric Router Security Update Advisory (CVE-2024-11980)

Overview

 

An update has been released to address vulnerabilities in Billion Electric Route. Users of the affected versions are advised to update to the latest version.
 

 

Affected Products

 

CVE-2024-11980

  • Billion Electric Firmware version: 1.04.1.592.x
  • Billion Electric Firmware version: 1.04.1.613.x
  • Billion Electric Firmware version: 1.04.1.x

 

 

Resolved Vulnerabilities

Authentication lapse vulnerability (CVE-2024-11980) in some Billion Electric router models that could allow remote attackers to view device information, change the WiFi SSID, or restart the device without authentication

 

 

Vulnerability Patches

Vulnerability patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

CVE-2024-11980

  • Billion Electric Firmware version: 1.04.1.592.8 or later version
  • Billion Electric Firmware version: 1.04.1.613.13 or later version
  • Billion Electric Firmware version: 1.04.1.675 or later version
     

 

Referenced Sites

 

[1] CVE-2024-11980 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-11980

[2] Billion Electric router – Missing Authentication

https://www.twcert.org.tw/en/cp-139-8274-01e55-2.html