ZeroHour

Vulnerabilities

20 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-42800
NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation.

NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program files sip/utils/src/sipuri.c.

NVD description · AI analysis pending
5.3<1%
  • asrmicro asr1901 firmware
  • asrmicro asr1903 firmware
CVE-2026-42799
Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers.

Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects Kestrel: before 2026/02/10.

NVD description · AI analysis pending
9.8<1%
  • asrmicro asr1803 firmware
CVE-2025-49492
Out-of-bounds write in ASR180x in lte-telephony, May cause a buffer underrun.

Out-of-bounds write in ASR180x in lte-telephony, May cause a buffer underrun. This vulnerability is associated with program files apps/atcmd_server/src/dev_api.C. This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536.

NVD description · AI analysis pending
9.8
group max
<1%
  • asrmicro falcon linux
  • asrmicro kestrel
  • asrmicro lapwing linux
CVE-2024-32634
In huge memory get unmapped area check, code can never be reached because of a logical contradiction.

In huge memory get unmapped area check, code can never be reached because of a logical contradiction.

NVD description · AI analysis pending
6.1<1%
  • asrmicro asr3603 firmware
  • asrmicro asr1607 firmware
  • asrmicro asr1803sc firmware
  • +1 more
CVE-2024-32632
+1 in the same advisory: …32633
A value in ATCMD will be misinterpreted by printf, causing incorrect output and possibly out-of-bounds memory access

A value in ATCMD will be misinterpreted by printf, causing incorrect output and possibly out-of-bounds memory access

NVD description · AI analysis pending
6.6
group max
<1%
  • asrmicro asr1803sc firmware
  • asrmicro asr1607 firmware
  • asrmicro asr3603 firmware
  • +1 more
CVE-2024-32631
Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations.

Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations.

NVD description · AI analysis pending
8.0<1%
  • asrmicro asr3602 firmware
  • asrmicro asr3605 firmware
  • asrmicro asr3607 firmware
  • +1 more
CVE-2024-32625
In OffloadAMRWriter, a scalar field is not initialized so will contain an arbitrary value left over from earlier computations

In OffloadAMRWriter, a scalar field is not initialized so will contain an arbitrary value left over from earlier computations

NVD description · AI analysis pending
5.8<1%
  • asrmicro asr1806 firmware
  • asrmicro asr1803 firmware
  • asrmicro asr1606 firmware
  • +1 more
CVE-2023-49701
+1 in the same advisory: …49700
Memory Corruption in SIM management while USIMPhase2init

Memory Corruption in SIM management while USIMPhase2init

NVD description · AI analysis pending
9.8
group max
<1%
  • asrmicro asr1803 firmware
  • asrmicro asr1806 firmware
CVE-2023-49699
Memory Corruption in IMS while calling VoLTE Streamingmedia Interface

Memory Corruption in IMS while calling VoLTE Streamingmedia Interface

NVD description · AI analysis pending
7.8<1%
  • asrmicro asr1806 firmware
  • asrmicro asr1803 firmware