CVE-2025-13735
7.4ASR Microelectronics · ASR Lapwing_Linux
An out-of-bounds read vulnerability exists in the nr_fw modules of ASR Lapwing_Linux, potentially allowing unauthorized data access or system instability.
Executive summary
An out-of-bounds read vulnerability in ASR Lapwing_Linux firmware could lead to information disclosure or system instability for authenticated users.
Vulnerability
This flaw is an out-of-bounds read vulnerability (CWE-125) located within the nr_fw module, specifically in the Code/nr_fw/DLP/src/NrCgi.C source file, which can be triggered by a low-privileged authenticated attacker.
Business impact
The vulnerability carries a CVSS score of 7.4, indicating a high severity risk that could lead to unauthorized information disclosure or a denial of service condition. Given that the impact involves potential system instability and the exposure of sensitive memory contents, organizations relying on ASR chipsets for network processing should prioritize mitigation to prevent service disruption or data leakage.
Remediation
Immediate Action: Update ASR Lapwing_Linux to the version released on or after 2025/11/26 as specified in the official vendor security advisory.
Proactive Monitoring: Review system and firewall logs for unusual crashes or error messages originating from the nr_fw module that may indicate exploitation attempts.
Compensating Controls: Implement strict network access controls to limit the number of users with the privileges required to reach the vulnerable NrCgi interface, thereby reducing the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The presence of an out-of-bounds read vulnerability in core firmware modules poses a significant risk to system integrity. Administrators must verify their current firmware version against the vendor documentation and apply the provided patch immediately to ensure the security of the affected devices.