CVE-2025-49162

Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow file overwrite via TFTP because a remote filename with a space character allows an attacker to control the local filename.
CVSS

No CVSS.

Configurations

No configuration.

History

03 Jun 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-03 00:15

Updated : 2025-06-03 00:15


NVD link : CVE-2025-49162

Mitre link : CVE-2025-49162


JSON object : View

Products Affected

No product.

CWE
CWE-424

Improper Protection of Alternate Path