Asr1803 Firmware
by Asrmicro
CVEs (9)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-42799 | Hig | 0.48 | 7.4 | 0.00 | Apr 30, 2026 | Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects Kestrel: before 2026/02/10. | ||
| CVE-2024-32631 | Hig | 0.47 | 7.2 | 0.00 | Apr 16, 2024 | Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations. | ||
| CVE-2023-49701 | Hig | 0.47 | 7.2 | 0.00 | Nov 30, 2023 | Memory Corruption in SIM management while USIMPhase2init | ||
| CVE-2023-49700 | Med | 0.44 | 6.7 | 0.00 | Nov 30, 2023 | Security best practices violations, a string operation in Streamingmedia will write past the end of fixed-size destination buffer if the source buffer is too large. | ||
| CVE-2023-49699 | Med | 0.44 | 6.7 | 0.00 | Nov 30, 2023 | Memory Corruption in IMS while calling VoLTE Streamingmedia Interface | ||
| CVE-2024-32632 | Med | 0.43 | 6.6 | 0.00 | Apr 16, 2024 | A value in ATCMD will be misinterpreted by printf, causing incorrect output and possibly out-of-bounds memory access | ||
| CVE-2024-32634 | Med | 0.40 | 6.1 | 0.00 | Apr 16, 2024 | In huge memory get unmapped area check, code can never be reached because of a logical contradiction. | ||
| CVE-2024-32625 | Med | 0.38 | 5.8 | 0.00 | Apr 16, 2024 | In OffloadAMRWriter, a scalar field is not initialized so will contain an arbitrary value left over from earlier computations | ||
| CVE-2024-32633 | Med | 0.26 | 4.0 | 0.00 | Apr 16, 2024 | An unsigned value can never be negative, so eMMC full disk test will always evaluate the same way. |
- risk 0.48cvss 7.4epss 0.00
Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects Kestrel: before 2026/02/10.
- risk 0.47cvss 7.2epss 0.00
Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations.
- risk 0.47cvss 7.2epss 0.00
Memory Corruption in SIM management while USIMPhase2init
- risk 0.44cvss 6.7epss 0.00
Security best practices violations, a string operation in Streamingmedia will write past the end of fixed-size destination buffer if the source buffer is too large.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in IMS while calling VoLTE Streamingmedia Interface
- risk 0.43cvss 6.6epss 0.00
A value in ATCMD will be misinterpreted by printf, causing incorrect output and possibly out-of-bounds memory access
- risk 0.40cvss 6.1epss 0.00
In huge memory get unmapped area check, code can never be reached because of a logical contradiction.
- risk 0.38cvss 5.8epss 0.00
In OffloadAMRWriter, a scalar field is not initialized so will contain an arbitrary value left over from earlier computations
- risk 0.26cvss 4.0epss 0.00
An unsigned value can never be negative, so eMMC full disk test will always evaluate the same way.