Executive brief
A NULL pointer dereference vulnerability in ASR's Kestrel modem chipset affects cellular baseband processing, potentially allowing authenticated network attackers to manipulate memory and cause service disruption or data corruption. The vulnerability resides in the radio resource control (as_rrc) module, which manages critical modem communications protocols. Exploitation requires network-level access and valid authentication credentials, limiting immediate risk to internal network attacks.
Technical details
A CWE-476 dereference-after-null-check vulnerability exists in the as_rrc module (file 3g.mod/lib/src/urrsir.c) of ASR Kestrel, exploitable via network access with low-privilege credentials. The flaw allows pointer manipulation that can corrupt memory within the modem's scope, affecting confidentiality, integrity, and availability across system boundaries. The issue affects Kestrel releases before 2026-09-20.
Affected products
- ASR ASR3603 before 2026-09-20
- ASR ASR1803 before 2026-09-20
- ASR ASR8661 before 2026-09-20
- ASR ASR1603 before 2026-09-20
Timeline
- 2026-09-23: disclosed: CVE-2026-42801 published
- 2026-09-20: patched: Fix available before this date (Kestrel)