CVE-2025-49480
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
01/07/2025
Last modified:
22/12/2025
Description
Out-of-bounds access in ASR180x 、ASR190x in lte-telephony, This vulnerability is associated with program files apps/lzma/src/LzmaEnc.c.<br />
<br />
This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536.
Impact
Base Score 3.x
7.40
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:asrmicro:falcon_linux:*:*:*:*:*:*:*:* | 1536 (excluding) | |
| cpe:2.3:o:asrmicro:kestrel:*:*:*:*:*:*:*:* | 1536 (excluding) | |
| cpe:2.3:o:asrmicro:lapwing_linux:*:*:*:*:*:*:*:* | 1536 (excluding) | |
| cpe:2.3:h:asrmicro:asr1803:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:asrmicro:asr1806:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:asrmicro:asr1901:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:asrmicro:asr1903:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



