VYPR
Vendor

Billion Electric

Products
2
CVEs
5
Across products
6
Status
Private

Products

2

Recent CVEs

5
  • CVE-2024-11980HigNov 29, 2024
    risk 0.56cvss 8.6epss 0.00

    Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device.

  • CVE-2025-1143HigFeb 11, 2025
    risk 0.55cvss 8.4epss 0.00

    Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in through the SSH service using these credentials and obtain root privilege of the system.

  • CVE-2024-11981HigNov 29, 2024
    risk 0.49cvss 7.5epss 0.01

    Certain models of routers from Billion Electric has an Authentication Bypass vulnerability, allowing unautheticated attackers to retrive contents of arbitrary web pages.

  • CVE-2024-11983HigNov 29, 2024
    risk 0.47cvss 7.2epss 0.01

    Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into a specific SSH function and execute them on the device.

  • CVE-2024-11982HigNov 29, 2024
    risk 0.47cvss 7.2epss 0.01

    Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers with administrator privileges can access the user settings page to retrieve plaintext passwords.