CVE-2026-42800General(asrmicro / asr1901)

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program files sip/utils/src/sipuri.c.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • asr1901
  • asr1901_firmware
  • asr1903
  • asr1903_firmware

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
asr1901asr1901_firmwareasr1903asr1903_firmware

1 version affected across 4 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-30: 3Technical Details · 2026-04-30: 304-30
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-42800 NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated w… https://www.cve.org/CVERecord?id=CVE-2026-42800

    Post summary

    The post briefly mentions CVE-2026-42800 as a NULL pointer dereference that permits pointer manipulation, but provides no Proof of Concept, exploit code, patch, or evidence of active exploitation.

    00020215
    57.7K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-42800 NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Man… CVSS 7.4 Full analysis → https://sec.kaitan.id/cves/CVE-2026-42800 #Linux #CyberSecurity #InfoSec

    Post summary

    The text announces CVE-2026-42800, a NULL pointer dereference vulnerability with CVSS 7.4, and provides a link to a full analysis but no PoC or exploitation details.

    1000029
    256 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-42800 NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated w… https://www.cve.org/CVERecord?id=CVE-2026-42800 ----- Traducción: CVE-2026-42800 vul… http://infoflow.cloud`

    Post summary

    The post briefly references CVE-2026-42800, mentioning a null‑pointer dereference issue in ASR Lapwing_Linux but offers no further details, solutions, or exploitation evidence.

    0000014
    74 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWasrmicroasr1901---
OSasrmicroasr1901_firmware---
HWasrmicroasr1903---
OSasrmicroasr1903_firmware---

Explore more