CVE-2025-61610

7.5

Unisoc (Shanghai) Technologies Co., Ltd. · T8100, T9100, T8200, T8300 Modems

An improper input validation flaw in Unisoc NR modems allows unauthenticated remote attackers to trigger a system crash, resulting in a denial of service.

Executive summary

A critical denial of service vulnerability exists in Unisoc modem firmware that allows unauthenticated remote attackers to crash affected mobile devices.

Vulnerability

The vulnerability is caused by improper input validation within the NR modem firmware, which can be exploited by an unauthenticated remote attacker to induce a system crash.

Business impact

The ability for a remote, unauthenticated attacker to cause a system crash poses a significant risk to device availability and operational continuity. Given the CVSS score of 7.5, this high-severity flaw could lead to widespread service disruption for mobile users, impacting both personal and enterprise communication workflows.

Remediation

Immediate Action: Monitor the official Unisoc support portal for firmware updates and apply them to affected devices as soon as they become available.

Proactive Monitoring: Security teams should monitor device logs for unexpected modem restarts or connectivity drops that may indicate exploitation attempts.

Compensating Controls: While direct mitigation is limited for modem firmware, users should maintain device security patches and restrict exposure to untrusted wireless networks where possible.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

This vulnerability presents a clear risk to device stability, and the lack of required privileges for an attacker makes it particularly concerning. Organizations deploying devices with Unisoc chipsets should prioritize the deployment of vendor security updates the moment they are released to prevent potential denial of service attacks.

More Unisoc (Shanghai) Technologies Co., Ltd. CVEs

Sources