CVE-2025-11131
7.5Unisoc · T8100/T9100/T8200/T8300 Modems
A vulnerability in Unisoc modem firmware allows unauthenticated remote attackers to trigger a system crash via improper input validation.
Executive summary
A critical vulnerability in Unisoc modem firmware poses a significant risk of remote denial of service, allowing attackers to crash affected mobile devices without user interaction.
Vulnerability
The flaw stems from improper input validation within the modem firmware, categorized as CWE-20. An unauthenticated remote attacker can exploit this weakness to cause a system crash, resulting in a denial of service.
Business impact
The exploitation of this vulnerability results in an immediate loss of device availability, which can disrupt critical communication and mobile services. With a CVSS score of 7.5, this high-severity issue is particularly concerning as it requires no user interaction or elevated privileges, making it a viable target for automated remote attacks against mobile infrastructure.
Remediation
Immediate Action: Users and administrators should check for and apply the latest security updates provided by the device manufacturer or mobile service provider.
Proactive Monitoring: Security teams should monitor device logs for unexpected system reboots or modem-related error codes that could indicate an exploitation attempt.
Compensating Controls: While direct mitigation on modem firmware is limited, maintaining updated Android security patches and avoiding untrusted network connections can reduce the overall attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high severity of this vulnerability and the potential for remote denial of service, prioritize the deployment of vendor-supplied firmware updates as soon as they become available. Ensure that all devices utilizing the affected Unisoc modem chipsets are included in patch management cycles to minimize the risk of service disruption.