CVE-2025-49162
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/06/2025
Last modified:
04/06/2025
Description
Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow file overwrite via TFTP because a remote filename with a space character allows an attacker to control the local filename.
Impact
Base Score 3.x
6.40
Severity 3.x
MEDIUM