The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker with access to the LAN network interface could use a specially crafted HTTP request to exploit a buffer overflow on the modem.
History

Sat, 26 Apr 2025 14:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 25 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 25 Apr 2025 13:15:00 +0000

Type Values Removed Values Added
Description The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker with access to the LAN network interface could use a specially crafted HTTP request to exploit a buffer overflow on the modem.
Title SNORE Interface Unauthenticated Remote Code Execution
Weaknesses CWE-120
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:N/AU:Y/R:U/V:C/RE:M/U:Red'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ONEKEY

Published: 2025-04-25T13:02:43.673Z

Updated: 2025-04-25T14:25:39.892Z

Reserved: 2024-06-20T09:18:03.225Z

Link: CVE-2024-6198

cve-icon Vulnrichment

Updated: 2025-04-25T14:25:36.736Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-25T13:15:42.370

Modified: 2025-04-29T13:52:28.490

Link: CVE-2024-6198

cve-icon Redhat

Severity : Important

Publid Date: 2025-04-25T13:02:43Z

Links: CVE-2024-6198 - Bugzilla