---
id: CVE-2026-42801
title: >-
  NULL pointer dereference vulnerability in ASR Crane，Falcon on Linux (as_rrc
  module) allows Pointer Manipulation.


  This vulnerability is associated with program file 3g.mod/lib/src/urrsir.c.
summary: >-
  NULL pointer dereference vulnerability in ASR Crane，Falcon on Linux (as_rrc
  module) allows Pointer Manipulation.


  This vulnerability is associated with program file 3g.mod/lib/src/urrsir.c.
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L'
cwe:
  - CWE-476
vendor: ASR
product: Crane，Falcon
affected:
  - Crane，Falcon
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:58:00.627'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42801'
references:
  - url: 'https://www.asrmicro.com/en/goods/psirt?cid=45'
    label: 68630edc-a58c-4cbd-9b01-0e130455c8ae
tags:
  - nvd
  - cve.org
epss: 0.00284
epssPercentile: 0.21139
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-23T15:25:08.195447Z'
ingestedAt: '2026-09-23T09:21:16.966Z'
---

## Overview

NULL pointer dereference vulnerability in ASR Crane，Falcon on Linux (as_rrc module) allows Pointer Manipulation.

This vulnerability is associated with program file 3g.mod/lib/src/urrsir.c.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
