
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-49483 is an Improper Resource Shutdown or Release vulnerability (CWE-404) affecting the TR-069 management module in ASR Micro's ASR180x and ASR190x chipset-based devices. The flaw resides in the tr069/tr069_uci.c source file and allows resource leak exposure. Affected firmware platforms include Falcon_Linux, Kestrel, and Lapwing_Linux versions prior to v1536. It was published on July 1, 2025, and carries a CVSS v3.1 base score of 5.4 (Medium) (ASR PSIRT, ENISA EUVD).
The vulnerability is classified as CWE-404 (Improper Resource Shutdown or Release) and is located in the TR-069 remote management module's tr069/tr069_uci.c file on ASR180x and ASR190x hardware platforms. When the TR-069 module processes certain requests, it fails to properly release allocated resources, resulting in a resource leak. Exploitation requires network access and low-level authentication (low privileges), with no user interaction needed, making it accessible to any authenticated user on the network (ASR PSIRT, ENISA EUVD).
Successful exploitation of this vulnerability can lead to low-level confidentiality and availability impacts. The resource leak in the TR-069 module may gradually degrade system performance over time and could expose sensitive information through unreleased memory or file handles. Integrity is not directly affected, and the scope remains unchanged, limiting the blast radius to the vulnerable device itself (ASR PSIRT, ENISA EUVD).
There is no public proof-of-concept exploit available for CVE-2025-49483, and no evidence of in-the-wild exploitation has been observed. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.037%, reflecting a very low probability of exploitation in the near term (ASR PSIRT, ENISA EUVD).
ASR Micro has released a patch addressing this vulnerability; affected organizations should upgrade Falcon_Linux, Kestrel, and Lapwing_Linux firmware to version v1536 or later. As a workaround, administrators should consider restricting network access to the TR-069 management interface to limit exposure to low-privilege attackers. Patch details and firmware updates are available through the ASR PSIRT advisory (ASR PSIRT).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."