CVE-2024-6198
SNORE Interface Unauthenticated Remote Code Execution
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker with access to the LAN network interface could use a specially crafted HTTP request to exploit a buffer overflow on the modem.
| CWE | CWE-120 |
| Vendor | viasat |
| Product | rm4100 |
| Published | Apr 25, 2025 |
| Last Updated | Feb 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for viasat rm4100
Be the first to know when new unknown vulnerabilities affecting viasat rm4100 are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
ViaSat / RM4100
0 < 3.8.0.4
Viasat / RM4200
0 < 3.8.0.4
Viasat / EM4100
0 < 3.8.0.4
Viasat / RM5110
0 ≤ 4.3.0.1
Viasat / RM5111
0 ≤ 4.3.0.1
Viasat / RG1000
0 ≤ 4.3.0.1
Viasat / RG1100
0 ≤ 4.3.0.1
Viasat / EG1000
0 ≤ 4.3.0.1
Viasat / EG1020
0 ≤ 4.3.0.1
References
Credits
Quentin Kaiser from ONEKEY Research Labs