PT-2025-27516 · Asr180X+3 · Asr180X+4

Published

2025-07-01

·

Updated

2025-12-22

·

CVE-2025-49480

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Falcon Linux versions prior to v1536 Kestrel versions prior to v1536 Lapwing Linux versions prior to v1536 ASR180x versions prior to v1536 ASR190x versions prior to v1536
Description: The issue is related to an out-of-bounds access in the lte-telephony component of the affected systems. This vulnerability is associated with the program files apps/lzma/src/LzmaEnc.c.
Recommendations: For Falcon Linux versions prior to v1536, update to version v1536 or later. For Kestrel versions prior to v1536, update to version v1536 or later. For Lapwing Linux versions prior to v1536, update to version v1536 or later. For ASR180x versions prior to v1536, update to version v1536 or later. For ASR190x versions prior to v1536, update to version v1536 or later.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2025-07951
CVE-2025-49480

Affected Products

Asr180X
Asr190X
Falcon Linux
Kestrel
Lapwing Linux