Firmware Decryption Key Exposure in Arris VIP1113 Devices
CVE-2025-49164
4.3MEDIUM
What is CVE-2025-49164?
The Arris VIP1113 devices, utilizing the KreaTV SDK, are impacted by a security issue where the firmware decryption key is improperly secured. This key, identified as cd1c2d78f2cba1f73ca7e697b4a485f49a8a7d0c8b0fdc9f51ced50f2530668a, remains accessible until a firmware update on May 30, 2025, potentially allowing unauthorized users to decrypt sensitive firmware data and gain elevated access to device functionalities.
Affected Version(s)
VIP1113 0 <= 2025-05-30