CVE-2025-49490 is a resource leak vulnerability in ASR180x routers, specifically affecting ASRMicro's Falcon_Linux, Kestrel, and Lapwing_Linux products before version v1536. This flaw, located in the router/sms/sms.c program file, could lead to resource exhaustion. Rated with a CVSS score of 5.3 (MEDIUM), this vulnerability is network-exploitable with low attack complexity and requires no user interaction or privileges. Its potential impact is limited to a denial of service (availability loss). Currently, there is no evidence of active exploitation, nor are there publicly available exploit codes in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1536CPE matchmatch criteria | cpe:2.3:o:asrmicro:falcon_linux:*:*:*:*:*:*:*:* | ||
< 1536CPE matchmatch criteria | cpe:2.3:o:asrmicro:kestrel:*:*:*:*:*:*:*:* | ||
< 1536CPE matchmatch criteria | cpe:2.3:o:asrmicro:lapwing_linux:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.