CVE-2025-49488 describes an Improper Resource Shutdown or Release vulnerability (CWE-404) in the router components of ASR180x and ASR190x devices, specifically affecting Falcon_Linux, Kestrel, and Lapwing_Linux versions prior to v1536. This flaw, located in router/phonebook/pb.c, can lead to Resource Leak Exposure. Rated as MEDIUM severity with a CVSS score of 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L), the vulnerability can be exploited remotely with low attack complexity, requiring no user interaction or privileges, and primarily impacts availability. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, aligning with the typical low attention for most vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1536CPE matchmatch criteria | cpe:2.3:o:asrmicro:falcon_linux:*:*:*:*:*:*:*:* | ||
< 1536CPE matchmatch criteria | cpe:2.3:o:asrmicro:kestrel:*:*:*:*:*:*:*:* | ||
< 1536CPE matchmatch criteria | cpe:2.3:o:asrmicro:lapwing_linux:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.