
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13735 is an Out-of-bounds Read vulnerability affecting ASR Lapwing_Linux on the ASR1903 and ASR3901 platforms (5G NR base station hardware). The flaw resides in the nr_fw modules, specifically in the source file Code/nr_fw/DLP/src/NrCgi.C. It was published on November 26, 2025, and affects all Lapwing_Linux versions prior to the 2025/11/26 patch release. The vulnerability carries a CVSS v3.1 base score of 7.4 (High) with a changed scope, indicating potential cross-component impact (ASR PSIRT, ENISA EUVD).
The vulnerability is classified as CWE-125 (Out-of-bounds Read), occurring in the NrCgi.C source file within the nr_fw (New Radio firmware) Data Link Processing (DLP) module of ASR's Lapwing_Linux. An authenticated network attacker can trigger the out-of-bounds read by sending crafted network requests, causing the software to read memory beyond the intended buffer boundaries. The attack vector is network-accessible, requires low privileges (authenticated access), no user interaction, and has low attack complexity, making it relatively straightforward to exploit for a credentialed attacker. The changed scope indicates that the impact can extend beyond the vulnerable component itself (ASR PSIRT, ENISA EUVD).
Successful exploitation results in low-level confidentiality, integrity, and availability impacts across a changed scope — meaning effects may propagate beyond the directly vulnerable nr_fw module to other system components. An authenticated attacker could leak sensitive memory contents (e.g., cryptographic material, configuration data, or other in-memory information), potentially cause partial service disruption or instability on affected ASR1903/ASR3901 5G base station hardware, and may achieve limited data manipulation. In a telecommunications infrastructure context, even partial compromise of base station firmware modules could have downstream effects on network availability and subscriber data (ASR PSIRT, ENISA EUVD).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-13735. The EPSS score is approximately 0.037% (0.000370), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, though CISA's weekly vulnerability bulletin for the week of November 24, 2025 referenced it. No threat actor attribution has been identified (CISA Bulletin, ENISA EUVD).
ASR has released a patch for Lapwing_Linux dated 2025/11/26; all versions prior to this date are affected and should be updated immediately. Operators of ASR1903 and ASR3901 5G base stations should apply the vendor-supplied firmware update available through ASR's PSIRT advisory. As a compensating control prior to patching, network access to the management and control interfaces of affected devices should be restricted to trusted, authenticated administrators only, minimizing the attack surface. No alternative workarounds beyond patching have been publicly documented (ASR PSIRT).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."