CVE Vulnerabilities

CVE-2025-49163

Improper Protection of Alternate Path

Published: Jun 03, 2025 | Modified: Jun 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file.

Weakness

The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.

Potential Mitigations

References