CVE-2024-6198: Viasat EG1000

High severity, CVSS 7.7. EPSS: 0.3% chance of exploitation in the next 30 days.

The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker with access to the LAN network interface could use a specially crafted HTTP request to exploit a buffer overflow on the modem.

Affected products

  • Viasat EG1000: up to and including 4.3.0.1
  • Viasat EG1020: up to and including 4.3.0.1
  • Viasat EM4100: before 3.8.0.4 (fixed in 3.8.0.4)
  • Viasat RG1000: up to and including 4.3.0.1
  • Viasat RG1100: up to and including 4.3.0.1
  • Viasat RM4100: before 3.8.0.4 (fixed in 3.8.0.4)
  • Viasat RM4200: before 3.8.0.4 (fixed in 3.8.0.4)
  • Viasat RM5110: up to and including 4.3.0.1
  • Viasat RM5111: up to and including 4.3.0.1

Published 2025-04-25. Last modified 2026-06-17.