PT-2025-17903 · Viasat · Eg1000+4

Quentin Kaiser

·

Published

2025-04-25

·

Updated

2025-05-15

·

CVE-2024-6199

CVSS v4.0

7.7

High

VectorAV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:M/U:Red
Name of the Vulnerable Software and Affected Versions The product name cannot be determined.
Description An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS services and the modem, could manipulate specific responses to include code that forces a buffer overflow on the modem. This issue is only exploitable on devices with Dynamic DNS enabled. Customers that have not enabled Dynamic DNS on their modem are not vulnerable.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-6199

Affected Products

Eg1000
Eg1020
Rg1100
Rm5110
Rm5111