CVE Vulnerabilities

CVE-2025-49162

Improper Protection of Alternate Path

Published: Jun 03, 2025 | Modified: Jun 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow file overwrite via TFTP because a remote filename with a space character allows an attacker to control the local filename.

Weakness

The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.

Potential Mitigations

References