CVE-2025-3012
7.5Unisoc · T8100/T9100/T8200/T8300 Modem
A null pointer dereference in the Unisoc modem firmware allows an unauthenticated remote attacker to cause a system crash, resulting in a denial of service condition.
Executive summary
A critical denial of service vulnerability in Unisoc modem firmware allows unauthenticated remote attackers to crash affected devices.
Vulnerability
The vulnerability involves a null pointer dereference within the dpc modem component. An unauthenticated attacker can trigger this condition remotely without requiring any specific user interaction or elevated privileges.
Business impact
Successful exploitation of this vulnerability results in a system crash, causing a denial of service for the device. Given the CVSS score of 7.5, this high severity flaw poses a significant risk to operational continuity, particularly for mobile devices relying on cellular connectivity for critical communication.
Remediation
Immediate Action: Consult the official Unisoc support portal for firmware updates corresponding to your specific device model and Android version.
Proactive Monitoring: Monitor device logs for unexpected modem restarts or recurring system stability issues that may indicate exploitation attempts.
Compensating Controls: While direct mitigation requires a vendor patch, ensure that device security policies are enforced and that only necessary network features are active to reduce the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability necessitates immediate attention from organizations deploying devices equipped with the affected Unisoc modem chipsets. Administrators should prioritize the deployment of manufacturer-provided firmware updates as soon as they become available to prevent remote denial of service attacks against their mobile fleet.