Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Asrmicro

First CVE: Nov 30, 2023Active for: 3 yearsTotal CVEs: 20
14.2
VTI Score
Low

Asrmicro's vulnerability footprint concentrates in a focused line of embedded systems and network appliances, including routers and specialized networking hardware such as the ASR series and Falcon Linux, that occupy a more prominent position in the landscape than its modest product count might suggest. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, though the exposure does not show a durable tendency toward public exploitation or confirmed in-the-wild deployment. The recurring weakness classes—improper resource management, out-of-bounds reads and writes, and classic buffer overflows—reflect the memory-safety demands of low-level firmware and embedded networking code, where unsafe pointer handling and incomplete bounds checking are endemic. Defenders should prioritize inventory and patching of affected appliances, particularly those exposed to untrusted network input. Current severity, exploitation status, and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Asrmicro over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 30, 2023
2 years ago
Most Recent CVE
Apr 30, 2026
85 days ago

Products(33 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-42799CRITICAL
Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C.
Apr 30, 20269.835NONO
CVE-2025-49480CRITICAL
Out-of-bounds access in ASR180x 、ASR190x in lte-telephony, This vulnerability is associated with program files apps/lzma/src/LzmaEnc.c. This issue affects Falcon_Linux、Kestrel、L
Jul 1, 20259.128NONO
CVE-2023-49701CRITICAL
Memory Corruption in SIM management while USIMPhase2init
Nov 30, 20239.827NONO
CVE-2025-49492CRITICAL
Out-of-bounds write in ASR180x in lte-telephony, May cause a buffer underrun.  This vulnerability is associated with program files apps/atcmd_server/src/dev_api.C. This issue aff
Jul 1, 20259.826NONO
CVE-2026-42800MEDIUM
NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program fi
Apr 30, 20265.324NONO
CVE-2023-49700HIGH
Security best practices violations, a string operation in Streamingmedia will write past the end of fixed-size destination buffer if the source buffer is too large.
Nov 30, 20237.522NONO
CVE-2023-49699HIGH
Memory Corruption in IMS while calling VoLTE Streamingmedia Interface
Nov 30, 20237.822NONO
CVE-2024-32631HIGH
Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations.
Apr 16, 20248.020NONO
CVE-2024-32632MEDIUM
A value in ATCMD will be misinterpreted by printf, causing incorrect output and possibly out-of-bounds memory access
Apr 16, 20246.619NONO
CVE-2024-32634MEDIUM
In huge memory get unmapped area check, code can never be reached because of a logical contradiction.
Apr 16, 20246.118NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
65%
15%
20%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.0%)
Network16 (80.0%)
Unknown0 (0.0%)
Physical2 (10.0%)
Adjacent Network1 (5.0%)
Attack Complexity
Low18 (90.0%)
High2 (10.0%)
Unknown0 (0.0%)
User Interaction
None19 (95.0%)
Unknown0 (0.0%)
Required1 (5.0%)
Privileges Required
Low3 (15.0%)
High2 (10.0%)
None15 (75.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Asrmicro.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Asrmicro — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Asrmicro's Products

View all 1 CNAs →

Top CWEs