Root code execution via unescaped TFTP filename
Published Jun 2, 2025 · Updated Jun 3, 2025
Command injection in the KreaTV bootloader on ARRIS VIP1113 devices through 2025-05-30 allows physically proximate attackers to overwrite files. The second-stage bootloader passes a hidden-menu TFTP remote filename into a command line without escaping spaces, shifting arguments so the local destination becomes attacker-controlled. Physical access to the device and boot configuration menu is required; replacing an executable and invoking it yields root code execution.
Summary
What happened
Command injection in the KreaTV bootloader on ARRIS VIP1113 devices through 2025-05-30 allows physically proximate attackers to overwrite files. The second-stage bootloader passes a hidden-menu TFTP remote filename into a command line without escaping spaces, shifting arguments so the local destination becomes attacker-controlled. Physical access to the device and boot configuration menu is required; replacing an executable and invoking it yields root code execution.
The record
- CVE
- CVE-2025-49162
- Published
- Jun 2, 2025
- Updated
- Jun 3, 2025
- Vendor
- ARRIS
- Product
- ARRIS VIP1113
- Classifications
- CWE-424, T1068
- Attack vector
- physical
- Privileges
- unauthenticated
Timeline
How it unfolded
- Jun 2, 2025CVE publishedPublication date reported by the CVE source.
- Jun 3, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <=2025-05-30
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- TFTP bootloader shell-injection proof of conceptfunctional · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo