CVE-2024-6198
Severity CVSS v4.0:
HIGH
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
25/04/2025
Last modified:
29/04/2025
Description
The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker<br />
with access to the LAN network interface could use a specially crafted HTTP request to exploit a buffer overflow on the modem.