CVE-2024-6198

Severity CVSS v4.0:
HIGH
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
25/04/2025
Last modified:
29/04/2025

Description

The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker<br /> with access to the LAN network interface could use a specially crafted HTTP request to exploit a buffer overflow on the modem.