CVE-2025-61609

7.5

Unisoc (Shanghai) Technologies Co., Ltd. · Modem T8100/T9100/T8200/T8300

A remote denial of service vulnerability exists in Unisoc modems due to improper input validation, allowing unauthenticated attackers to cause a system crash.

Executive summary

A critical vulnerability in Unisoc modem firmware allows unauthenticated remote attackers to trigger a system crash, resulting in a denial of service.

Vulnerability

The flaw is caused by improper input validation within the modem firmware. An unauthenticated attacker can exploit this via the network to trigger a system crash, as no additional execution privileges are required.

Business impact

The ability for an unauthenticated remote attacker to crash a device modem poses a significant risk to service availability. This vulnerability could lead to widespread disruption of mobile connectivity for end users, potentially impacting business operations that rely on cellular data. Given the CVSS score of 7.5, this is considered a High severity issue that requires prioritized attention to maintain infrastructure stability.

Remediation

Immediate Action: Consult the official Unisoc support announcement to determine if a firmware update is available for your specific device model and carrier implementation.

Proactive Monitoring: Monitor device logs for unexpected modem restarts, signal drops, or recurring system stability issues that may indicate exploitation attempts.

Compensating Controls: While direct mitigation is limited for firmware-level issues, ensure that devices are managed through enterprise mobility management solutions to enforce security policies and monitor for anomalous network behavior.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability represents a significant risk to mobile device availability due to the ease of remote exploitation. Security teams should prioritize identifying affected hardware within their environment and work with device manufacturers or service providers to obtain the necessary firmware patches. Immediate action is required to minimize the window of exposure to potential denial of service attacks.

More Unisoc (Shanghai) Technologies Co., Ltd. CVEs

Sources