CVE-2025-49480 describes a critical out-of-bounds access vulnerability in the lte-telephony component of ASR180x and ASR190x series products, specifically within the apps/lzma/src/LzmaEnc.c program file. This flaw impacts multiple ASRMicro products, including Falcon_Linux, Kestrel, and Lapwing_Linux versions prior to v1536. With a CVSS score of 9.1 (CRITICAL), this vulnerability is remotely exploitable without authentication (AV:N/AC:L/PR:N/UI:N), allowing for high confidentiality and availability impacts (C:H/A:H). The underlying issue is a CWE-125 (Out-of-bounds Read), indicating a fundamental memory safety problem. Currently, there is no evidence of active exploitation, and no public exploit code or Metasploit/Nuclei modules are available. Despite the lack of media coverage, the vulnerability has garnered significant community discussion with 10 mentions, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1536CPE matchmatch criteria | cpe:2.3:o:asrmicro:falcon_linux:*:*:*:*:*:*:*:* | ||
< 1536CPE matchmatch criteria | cpe:2.3:o:asrmicro:kestrel:*:*:*:*:*:*:*:* | ||
< 1536CPE matchmatch criteria | cpe:2.3:o:asrmicro:lapwing_linux:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.