CVE-2025-11133
7.5Unisoc (Shanghai) Technologies Co., Ltd. · T8100, T9100, T8200, T8300 Modems
A vulnerability in Unisoc modem firmware allows unauthenticated attackers to trigger a system crash via improper input validation, leading to a remote denial of service.
Executive summary
A remote denial of service vulnerability exists in multiple Unisoc modem chipsets that allows unauthenticated attackers to crash the system via improper input validation.
Vulnerability
This flaw is caused by improper input validation (CWE-20) within the modem firmware. An unauthenticated attacker can exploit this remotely without requiring any specific user interaction or elevated privileges to cause a system crash.
Business impact
The ability for an unauthenticated remote attacker to force a system crash presents a significant availability risk for mobile devices utilizing these chipsets. With a CVSS score of 7.5, this high severity issue could disrupt critical communication services and business operations by rendering devices non-functional until a reboot occurs.
Remediation
Immediate Action: Consult the official Unisoc security announcement at the provided reference link and apply all relevant firmware updates as soon as they are made available by your device manufacturer.
Proactive Monitoring: Monitor device logs for unexpected reboots or modem service restarts that may indicate successful exploitation attempts.
Compensating Controls: Since this vulnerability exists at the firmware level, standard network-based WAFs may provide limited protection, making the application of vendor-supplied patches the only reliable mitigation.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the remote exploitability and the potential for full service denial, this vulnerability poses a substantial risk to device availability. Organizations should prioritize updating affected mobile hardware as soon as the manufacturer releases the necessary firmware patches to ensure the stability and security of their mobile fleet.