CVE-2024-6198 - CVE House
Back to Database
Status published High CVE-2024-6198

SNORE Interface Unauthenticated Remote Code Execution

Vulnerability Description

The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker with access to the LAN network interface could use a specially crafted HTTP request to exploit a buffer overflow on the modem.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-6198

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Quentin Kaiser from ONEKEY Research Labs

Affected Vendor

Affected Software

RM4100, RM4200, EM4100, RM5110, RM5111, RG1000, RG1100, EG1000, EG1020
Vulnerable Versions:
0

Timeline

Official Publish: April 25th, 2025
Last Modified: February 26th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)