ASR Microelectronics Co., Ltd.
First CVE: Nov 30, 2023Active for: 3 years
21
CVEs Published
More CVEs Published than 41% of tracked CNAs
5.3
Avg CVEs / Year
More Avg CVEs / Year than 34% of tracked CNAs
6.7
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by ASR Microelectronics Co., Ltd. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 30, 2023
2 years ago
Most Recent CVE
Apr 30, 2026
86 days ago
Top CVEs
All CVEs published by ASR Microelectronics Co., Ltd. as a CNA, regardless of affected vendor or product.
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42799CRITICAL Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers.
This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C.
| Apr 30, 2026 | 9.8 | 35 | NO | NO |
CVE-2025-49480CRITICAL Out-of-bounds access in ASR180x 、ASR190x in lte-telephony, This vulnerability is associated with program files apps/lzma/src/LzmaEnc.c.
This issue affects Falcon_Linux、Kestrel、L | Jul 1, 2025 | 9.1 | 28 | NO | NO |
CVE-2023-49701CRITICAL Memory Corruption in SIM management while USIMPhase2init | Nov 30, 2023 | 9.8 | 27 | NO | NO |
CVE-2025-49492CRITICAL Out-of-bounds write in ASR180x in lte-telephony, May cause a buffer underrun. This vulnerability is associated with program files apps/atcmd_server/src/dev_api.C.
This issue aff | Jul 1, 2025 | 9.8 | 26 | NO | NO |
CVE-2025-13735HIGH Out-of-bounds Read vulnerability in ASR1903、ASR3901 in ASR Lapwing_Linux on Linux (nr_fw modules). This vulnerability is associated with program files Code/nr_fw/DLP/src/NrCgi.C.
| Nov 26, 2025 | 7.4 | 25 | NO | NO |
CVE-2026-42800MEDIUM NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation.
This vulnerability is associated with program fi | Apr 30, 2026 | 5.3 | 24 | NO | NO |
CVE-2023-49700HIGH Security best practices violations, a string operation in Streamingmedia will write past the end of fixed-size destination buffer if the source buffer is too large. | Nov 30, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-49699HIGH Memory Corruption in IMS while calling VoLTE Streamingmedia Interface | Nov 30, 2023 | 7.8 | 22 | NO | NO |
CVE-2024-32631HIGH Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations. | Apr 16, 2024 | 8.0 | 20 | NO | NO |
CVE-2024-32632MEDIUM A value in ATCMD will be misinterpreted by printf, causing incorrect output and possibly out-of-bounds memory access | Apr 16, 2024 | 6.6 | 19 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA21 CVEs
62%
19%
19%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.8%)
Network17 (81.0%)
Unknown0 (0.0%)
Physical2 (9.5%)
Adjacent Network1 (4.8%)
Attack Complexity
Low19 (90.5%)
High2 (9.5%)
Unknown0 (0.0%)
User Interaction
None20 (95.2%)
Unknown0 (0.0%)
Required1 (4.8%)
Privileges Required
Low4 (19.0%)
High2 (9.5%)
None15 (71.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (21 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by ASR Microelectronics Co., Ltd. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by ASR Microelectronics Co., Ltd. as a CNA — matched by CVE ID, not by organization name.