CVE-2026-42799

7.4

ASR Kestrel · Kestrel

An out-of-bounds read vulnerability in the ASR Kestrel nr_fw modules allows for potential buffer overflows.

Executive summary

A high-severity out-of-bounds read vulnerability in ASR Kestrel firmware, identified as CVE-2026-42799, poses a risk of unauthorized data access and potential system disruption.

Vulnerability

This vulnerability is an out-of-bounds read (CWE-125) located in the nr_fw modules, specifically within the source file Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. The vulnerability requires low privileges for exploitation and can be triggered by an attacker over the network.

Business impact

The vulnerability carries a CVSS score of 7.4, indicating a high level of risk to operational environments. Successful exploitation may lead to unauthorized disclosure of sensitive information, integrity compromise, or denial of service, potentially resulting in significant system downtime or loss of confidentiality regarding internal device processes.

Remediation

Immediate Action: Organizations should verify their firmware version and apply the latest security updates provided by ASR Kestrel immediately to address the identified memory safety flaw.

Proactive Monitoring: Security teams should review system access logs for anomalous traffic patterns or unexpected behavior originating from the network segment where Kestrel devices are deployed.

Compensating Controls: Implement strict network segmentation to limit the reach of unauthorized users and utilize intrusion detection systems to monitor for traffic targeting the nr_fw module service endpoints.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for buffer overflow conditions, this vulnerability should be treated as a priority for remediation. Administrators must identify all instances of the affected firmware and coordinate with the vendor to ensure the latest patches are applied to eliminate the underlying memory safety issue and prevent potential exploitation.

Sources