CVE-2025-13735

7.4

ASR Microelectronics · ASR Lapwing_Linux

An out-of-bounds read vulnerability exists in the nr_fw modules of ASR Lapwing_Linux, potentially allowing unauthorized data access or system instability.

Executive summary

An out-of-bounds read vulnerability in ASR Lapwing_Linux firmware could lead to information disclosure or system instability for authenticated users.

Vulnerability

This flaw is an out-of-bounds read vulnerability (CWE-125) located within the nr_fw module, specifically in the Code/nr_fw/DLP/src/NrCgi.C source file, which can be triggered by a low-privileged authenticated attacker.

Business impact

The vulnerability carries a CVSS score of 7.4, indicating a high severity risk that could lead to unauthorized information disclosure or a denial of service condition. Given that the impact involves potential system instability and the exposure of sensitive memory contents, organizations relying on ASR chipsets for network processing should prioritize mitigation to prevent service disruption or data leakage.

Remediation

Immediate Action: Update ASR Lapwing_Linux to the version released on or after 2025/11/26 as specified in the official vendor security advisory.

Proactive Monitoring: Review system and firewall logs for unusual crashes or error messages originating from the nr_fw module that may indicate exploitation attempts.

Compensating Controls: Implement strict network access controls to limit the number of users with the privileges required to reach the vulnerable NrCgi interface, thereby reducing the attack surface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The presence of an out-of-bounds read vulnerability in core firmware modules poses a significant risk to system integrity. Administrators must verify their current firmware version against the vendor documentation and apply the provided patch immediately to ensure the security of the affected devices.

More ASR Microelectronics CVEs

Sources