CVE-2025-61608
7.5Unisoc (Shanghai) Technologies Co., Ltd. · T8100/T9100/T8200/T8300 Modems
A remote denial of service vulnerability exists in Unisoc modem firmware due to improper input validation, allowing unauthenticated attackers to trigger a system crash.
Executive summary
A critical vulnerability in Unisoc modem firmware allows unauthenticated remote attackers to trigger a system crash, resulting in a denial of service.
Vulnerability
The vulnerability stems from improper input validation (CWE-20) within the nr modem software. This flaw permits an unauthenticated attacker to remotely cause a system crash, impacting device availability.
Business impact
Successful exploitation of this vulnerability results in a denial of service, rendering the affected mobile or embedded device unresponsive. With a CVSS score of 7.5, the risk is classified as High due to the lack of required authentication and the ease of network-based exploitation. Business operations relying on these devices for communication or data connectivity may face significant disruption.
Remediation
Immediate Action: Monitor the official Unisoc support portal for the release of security patches and apply firmware updates to affected hardware as soon as they become available.
Proactive Monitoring: Review system logs for unexpected modem resets or intermittent connectivity loss that may indicate attempted exploitation.
Compensating Controls: While direct network-level mitigation is difficult for modem-specific flaws, ensure that devices are isolated from untrusted networks where possible to limit the exposure of the baseband processor.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for remote denial of service on widely deployed cellular hardware, organizations using affected Unisoc-based devices should prioritize tracking vendor security bulletins. Once a patch is released by the device manufacturer or Unisoc, it should be deployed across the fleet immediately to prevent service outages.