CVE-2025-49162: Medium severity arris vip1113 vulnerability
Published Jun 2, 2025
·Updated
Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow file overwrite via TFTP because a remote filename with a space character allows an attacker to control the local filename.
Affected Software
1 affected component
Arris VIP1113<=2025-05-30
Event History
Jun 2, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Jun 3, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-49162?
CVE-2025-49162 has been identified as a high severity vulnerability due to its ability to allow an attacker to control file overwrites.
2
How do I fix CVE-2025-49162?
To fix CVE-2025-49162, update your Arris VIP1113 devices to a version released after May 30, 2025.
3
What types of devices are affected by CVE-2025-49162?
CVE-2025-49162 affects Arris VIP1113 devices running KreaTV SDK up to the date of May 30, 2025.
4
Can CVE-2025-49162 be exploited remotely?
Yes, CVE-2025-49162 can be exploited remotely through TFTP by manipulating the filename.
5
What impact does CVE-2025-49162 have on a device?
CVE-2025-49162 allows an attacker to overwrite files on the device, potentially leading to further compromise.