CVE-2024-6199 – “Huawei Modem DDNS Buffer Overflow Vulnerability”

The following table lists the changes that have been made to the
CVE-2024-6199 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Apr. 25, 2025

    Action Type Old Value New Value
    Added Description An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS services and the modem, could manipulate specific responses to include code that forces a buffer overflow on the modem.

    Customers that have not enabled Dynamic DNS on their modem are not vulnerable.

    Added CVSS V4.0 AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:M/U:Red
    Added CWE CWE-120
    Added Reference https://www.onekey.com/resource/security-advisory-rce-on-viasat-modems-cve-2024-6199
Share the Post:

Related Posts