CVE-2025-49492: Out-of-bounds write in lte-telephony
Published Jul 1, 2025
·Updated
Out-of-bounds write in ASR180x in lte-telephony, May cause a buffer underrun. This vulnerability is associated with program files apps/atcmdserver/src/devapi.C.
This issue affects FalconLinux、Kestrel、LapwingLinux: before v1536.
Affected Software
10 affected components
Unknown Falcon_Linux<v1536
Unknown Kestrel<v1536
Unknown Lapwing_Linux<v1536
All of the following
Any of the following
Asrmicro Falcon Linux<1536
Asrmicro Kestrel<1536
Asrmicro Lapwing Linux<1536
Any of the following
Asrmicro Asr1803
Asrmicro Asr1806
Asrmicro Asr1901
Asrmicro Asr1903
Event History
Jul 1, 2025
CVE Published
via MITRE·10:52 AM
Data Sourced
via MITRE·10:52 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Nov 15, 57945
Event
via NVD·02:10 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-49492?
CVE-2025-49492 is classified as a high severity vulnerability due to its potential to cause buffer underruns.
2
How do I fix CVE-2025-49492?
To mitigate CVE-2025-49492, update Falcon_Linux, Kestrel, and Lapwing_Linux to versions beyond v1536.
3
What systems are affected by CVE-2025-49492?
CVE-2025-49492 affects Falcon_Linux, Kestrel, and Lapwing_Linux versions before v1536.
4
What is the nature of the vulnerability in CVE-2025-49492?
CVE-2025-49492 is an out-of-bounds write vulnerability in the ASR180x system that may lead to a buffer underrun.
5
When was CVE-2025-49492 reported?
CVE-2025-49492 was reported in May and impacts various telephony applications.