
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-49492 is an out-of-bounds write vulnerability in the ASR180x LTE-telephony module (specifically in apps/atcmd_server/src/dev_api.C) that may cause a buffer underrun condition. It affects ASR Micro's Falcon_Linux, Kestrel, and Lapwing_Linux operating systems in all versions prior to v1536. The vulnerability was published on July 1, 2025, and carries a CVSS v3.1 base score of 9.8 (Critical) per NVD, reflecting unauthenticated remote exploitability with no user interaction required (ASR PSIRT).
The vulnerability is classified as CWE-787 (Out-of-bounds Write) and resides in the AT command server component of the ASR180x LTE-telephony stack, specifically in the source file apps/atcmd_server/src/dev_api.C. An attacker can trigger a buffer underrun by sending maliciously crafted network input to the affected component, causing writes to memory locations outside the intended buffer boundaries. No authentication or user interaction is required, and attack complexity is low, making this exploitable by any network-accessible attacker (ASR PSIRT).
Successful exploitation of this vulnerability can result in complete compromise of the affected device, with high impact to confidentiality, integrity, and availability. An unauthenticated remote attacker could achieve arbitrary code execution, manipulate system data, or cause a denial-of-service condition on affected LTE modem/telephony platforms. Given the embedded/IoT nature of the ASR180x chipset, exploitation could affect cellular connectivity and potentially enable persistent access to the underlying system (ASR PSIRT).
As of the time of publication, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.037%, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the critical CVSS score and unauthenticated network attack vector make it a high-priority patching target (ASR PSIRT).
ASR Micro has released a patch addressing this vulnerability. Affected users should update all impacted platforms — Falcon_Linux, Kestrel, and Lapwing_Linux — to version v1536 or later. No specific workarounds have been publicly documented; upgrading to the patched firmware version is the recommended and primary remediation action. Administrators should monitor affected systems for anomalous behavior while updates are being deployed (ASR PSIRT).
The vulnerability received routine aggregation coverage from vulnerability tracking platforms including Vulners, VulDB, CIRCL, and CVEFeed shortly after its July 1, 2025 publication. It was also referenced in CISA's weekly vulnerability bulletin for the week of June 30, 2025. No notable independent researcher commentary or significant media coverage has been identified beyond standard automated vulnerability feeds (CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."