### [CVE-2025-49162](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-49162) ![](https://img.shields.io/static/v1?label=Product&message=VIP1113&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=0%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-424%20Improper%20Protection%20of%20Alternate%20Path&color=brightgreen) ### Description Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow file overwrite via TFTP because a remote filename with a space character allows an attacker to control the local filename. ### POC #### Reference - https://full-disclosure.eu/reports/2025/FDEU-CVE-2025-1c00-arris-bootloader-shell-injection.html #### Github No PoCs found on GitHub currently.