CVE-2024-6198: Viasat EG1000
High severity, CVSS 7.7. EPSS: 0.3% chance of exploitation in the next 30 days.
The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker with access to the LAN network interface could use a specially crafted HTTP request to exploit a buffer overflow on the modem.
Affected products
- Viasat EG1000: up to and including 4.3.0.1
- Viasat EG1020: up to and including 4.3.0.1
- Viasat EM4100: before 3.8.0.4 (fixed in 3.8.0.4)
- Viasat RG1000: up to and including 4.3.0.1
- Viasat RG1100: up to and including 4.3.0.1
- Viasat RM4100: before 3.8.0.4 (fixed in 3.8.0.4)
- Viasat RM4200: before 3.8.0.4 (fixed in 3.8.0.4)
- Viasat RM5110: up to and including 4.3.0.1
- Viasat RM5111: up to and including 4.3.0.1
Published 2025-04-25. Last modified 2026-06-17.