CVE-2025-11132
7.5Unisoc (Shanghai) Technologies Co., Ltd. · T8100/T9100/T8200/T8300 Modems
A vulnerability in Unisoc modems allows unauthenticated remote attackers to trigger a system crash via improper input validation.
Executive summary
The Unisoc modem vulnerability permits a remote denial of service attack, posing a significant stability risk to affected mobile devices.
Vulnerability
The flaw is caused by improper input validation (CWE-20) within the modem firmware. An unauthenticated remote attacker can supply crafted input to the modem to force a system crash, resulting in a denial of service.
Business impact
The ability for a remote attacker to crash the modem without any privileges or user interaction represents a high risk to availability. With a CVSS score of 7.5, this vulnerability could be leveraged to disrupt communications for mobile users, potentially impacting business continuity for organizations relying on these devices for mobile connectivity and remote workforce operations.
Remediation
Immediate Action: Check for and apply the latest firmware or security patch provided by your device manufacturer or mobile service provider.
Proactive Monitoring: Monitor device stability and connectivity logs for unexpected modem resets or intermittent network drops that may indicate exploitation attempts.
Compensating Controls: While direct mitigation is limited for mobile hardware, ensure that device security policies are enforced and that only necessary network features are enabled.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for remote denial of service and the automatable nature of this vulnerability, administrators should prioritize the deployment of vendor-supplied security updates as soon as they become available. Users should remain vigilant for device instability and ensure their systems are running the most current firmware version to mitigate the risk of exploitation.