Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Billion

First CVE: May 2, 2019Active for: 7 yearsTotal CVEs: 10
80.1
VTI Score
TOP TARGET

Billion manufactures a narrow line of networking and routing appliances, primarily the 5200W-T series and SG600 R2, that occupy a modest but strategically important niche in small-business and branch-office deployments. Vulnerabilities affecting this vendor skew strongly toward critical severity and frequently acquire public exploit code; the exposure recurs across these product lines through embedded-system weakness classes including OS command injection, hard-coded credentials, and cross-site scripting that reflect the security-sensitive nature of administrative interfaces in network appliances. Defenders should treat firmware updates for these devices as high-priority and restrict management access; live exploitation and severity counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
8.7
Avg CVSS Score
Higher Avg CVSS Score than 83% of tracked vendors
10.0%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Billion over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2019
7 years ago
Most Recent CVE
Jan 9, 2020
2,388 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-18368CRITICAL
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding functi
May 2, 20199.897YESYES
CVE-2017-18369CRITICAL
The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an un
May 2, 20199.878NOYES
CVE-2017-18371CRITICAL
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the
May 2, 20199.854NOYES
CVE-2017-18370HIGH
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is only acce
May 2, 20198.852NOYES
CVE-2017-18372HIGH
The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting function, which is only accessible by
May 2, 20198.851NOYES
CVE-2017-18374HIGH
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has two user accounts with default passwords, including a hardcoded service acco
May 2, 20198.830NONO
CVE-2017-18373HIGH
The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one w
May 2, 20198.830NONO
CVE-2019-14920HIGH
Billion Smart Energy Router SG600R2 Firmware v3.02.rc6 allows an authenticated attacker to gain root execution privileges over the device via a hidden etc_ro/web/adm/system_command
Jan 9, 20208.826NONO
CVE-2019-14919HIGH
An exposed Telnet Service on the Billion Smart Energy Router SG600R2 with firmware v3.02.rc6 allows a local network attacker to authenticate via hardcoded credentials into a shell,
Jan 9, 20207.824NONO
CVE-2019-14918MEDIUM
XSS in the DHCP lease-status table in Billion Smart Energy Router SG600R2 Firmware v3.02.rc6 allows an attacker to inject arbitrary HTML/JavaScript code to achieve client-side code
Jan 9, 20205.419NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
10%
60%
30%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (10.0%)
Network9 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low7 (70.0%)
High0 (0.0%)
None3 (30.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
1 CVE
10.0% of CVEs· 100th percentile
Metasploit
5 CVEs
50.0% of CVEs· 99th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Billion.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Billion — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Billion's Products

View all 1 CNAs →

Top CWEs