CVE-2025-3012

7.5

Unisoc · T8100/T9100/T8200/T8300 Modem

A null pointer dereference in the Unisoc modem firmware allows an unauthenticated remote attacker to cause a system crash, resulting in a denial of service condition.

Executive summary

A critical denial of service vulnerability in Unisoc modem firmware allows unauthenticated remote attackers to crash affected devices.

Vulnerability

The vulnerability involves a null pointer dereference within the dpc modem component. An unauthenticated attacker can trigger this condition remotely without requiring any specific user interaction or elevated privileges.

Business impact

Successful exploitation of this vulnerability results in a system crash, causing a denial of service for the device. Given the CVSS score of 7.5, this high severity flaw poses a significant risk to operational continuity, particularly for mobile devices relying on cellular connectivity for critical communication.

Remediation

Immediate Action: Consult the official Unisoc support portal for firmware updates corresponding to your specific device model and Android version.

Proactive Monitoring: Monitor device logs for unexpected modem restarts or recurring system stability issues that may indicate exploitation attempts.

Compensating Controls: While direct mitigation requires a vendor patch, ensure that device security policies are enforced and that only necessary network features are active to reduce the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates immediate attention from organizations deploying devices equipped with the affected Unisoc modem chipsets. Administrators should prioritize the deployment of manufacturer-provided firmware updates as soon as they become available to prevent remote denial of service attacks against their mobile fleet.

More Unisoc CVEs

Sources