PT-2025-23559 · Unknown+1 · Kreatv Sdk+1

Published

2025-06-02

·

Updated

2025-06-03

·

CVE-2025-49162

CVSS v3.1

6.4

Medium

VectorAV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Arris VIP1113 devices with KreaTV SDK through 2025-05-30
Description The issue allows file overwrite via TFTP because a remote filename with a space character enables an attacker to control the local filename.
Recommendations For Arris VIP1113 devices with KreaTV SDK through 2025-05-30, consider restricting TFTP access until a patch is available to prevent file overwrite attacks.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-49162

Affected Products

Arris Vip1113
Kreatv Sdk