CVE-2025-49163: Medium severity arris vip1113 vulnerability
Published Jun 2, 2025
·Updated
Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file.
Affected Software
1 affected component
Arris VIP1113<=2025-05-30
Event History
Jun 2, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Jun 3, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-49163?
CVE-2025-49163 is classified as a critical vulnerability due to the potential for arbitrary image booting.
2
How do I fix CVE-2025-49163?
To mitigate CVE-2025-49163, users should update Arris VIP1113 devices to a version released after May 30, 2025.
3
What devices are affected by CVE-2025-49163?
CVE-2025-49163 affects Arris VIP1113 devices that have not been updated beyond the version available until May 30, 2025.
4
What type of attack does CVE-2025-49163 facilitate?
CVE-2025-49163 facilitates bootloader shell injection attacks by exploiting a crafted gunzip file.
5
Is it safe to use the Arris VIP1113 device after updating for CVE-2025-49163?
After applying the necessary updates for CVE-2025-49163, the device's security should be significantly improved.