CVE-2026-42799 Details
Description
Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects Kestrel: before 2026/02/10.
A vulnerability allowing out-of-bounds read operations has been identified in ASR Kestrel, specifically in the nr_fw modules. This issue can lead to buffer overflow conditions. The vulnerability is present in Kestrel versions prior to February 10, 2026.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.asrmicro.com/en/goods/psirt?cid=44 | ASR Microelectronics Co., Ltd. | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | ASR Microelectronics Co., Ltd. |
Affected Products
| Product | Versions |
|---|---|
| asrmicro asr1803 firmware | < 1.216.002 |
CPE
Remediation
| |
| asrmicro asr1803 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ASR Microelectronics Co., Ltd. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 5, 2026 | Initial Analysis | [email protected] |
| Apr 30, 2026 | New CVE Received | ASR Microelectronics Co., Ltd. |