Asrmicro's vulnerability footprint concentrates in a focused line of embedded systems and network appliances, including routers and specialized networking hardware such as the ASR series and Falcon Linux, that occupy a more prominent position in the landscape than its modest product count might suggest. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, though the exposure does not show a durable tendency toward public exploitation or confirmed in-the-wild deployment. The recurring weakness classes—improper resource management, out-of-bounds reads and writes, and classic buffer overflows—reflect the memory-safety demands of low-level firmware and embedded networking code, where unsafe pointer handling and incomplete bounds checking are endemic. Defenders should prioritize inventory and patching of affected appliances, particularly those exposed to untrusted network input. Current severity, exploitation status, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Asrmicro over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42799CRITICAL Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers.
This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C.
| Apr 30, 2026 | 9.8 | 35 | NO | NO |
CVE-2025-49480CRITICAL Out-of-bounds access in ASR180x 、ASR190x in lte-telephony, This vulnerability is associated with program files apps/lzma/src/LzmaEnc.c.
This issue affects Falcon_Linux、Kestrel、L | Jul 1, 2025 | 9.1 | 28 | NO | NO |
CVE-2023-49701CRITICAL Memory Corruption in SIM management while USIMPhase2init | Nov 30, 2023 | 9.8 | 27 | NO | NO |
CVE-2025-49492CRITICAL Out-of-bounds write in ASR180x in lte-telephony, May cause a buffer underrun. This vulnerability is associated with program files apps/atcmd_server/src/dev_api.C.
This issue aff | Jul 1, 2025 | 9.8 | 26 | NO | NO |
CVE-2026-42800MEDIUM NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation.
This vulnerability is associated with program fi | Apr 30, 2026 | 5.3 | 24 | NO | NO |
CVE-2023-49700HIGH Security best practices violations, a string operation in Streamingmedia will write past the end of fixed-size destination buffer if the source buffer is too large. | Nov 30, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-49699HIGH Memory Corruption in IMS while calling VoLTE Streamingmedia Interface | Nov 30, 2023 | 7.8 | 22 | NO | NO |
CVE-2024-32631HIGH Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations. | Apr 16, 2024 | 8.0 | 20 | NO | NO |
CVE-2024-32632MEDIUM A value in ATCMD will be misinterpreted by printf, causing incorrect output and possibly out-of-bounds memory access | Apr 16, 2024 | 6.6 | 19 | NO | NO |
CVE-2024-32634MEDIUM In huge memory get unmapped area check, code can never be reached because of a logical contradiction. | Apr 16, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Asrmicro.
Media articles that mention a CVE ID that affects a product developed by Asrmicro — matched by CVE ID, not by vendor name.