CVE-2025-61614

7.5

Unisoc · nr modem

A vulnerability in the Unisoc nr modem allows for a remote system crash due to improper input validation.

Executive summary

A high-severity vulnerability in Unisoc nr modem firmware allows unauthenticated remote attackers to trigger a system crash via improper input validation.

Vulnerability

This vulnerability is caused by improper input validation within the nr modem component. An unauthenticated attacker can exploit this flaw to cause a remote denial of service, effectively crashing the system without requiring any additional execution privileges.

Business impact

Successful exploitation of this vulnerability results in a denial of service, which can lead to significant operational downtime for affected mobile devices. Given the CVSS score of 7.5, this is categorized as a high-severity issue because it allows for remote, unauthenticated disruption of critical system functions.

Remediation

Immediate Action: Monitor the Unisoc support portal for official security patches and apply them to all affected devices as soon as they become available.

Proactive Monitoring: Security teams should monitor device logs for unexpected modem restarts or system instability that may indicate attempts to trigger this crash.

Compensating Controls: Since this is a low-level firmware vulnerability, there are limited compensating controls available, though maintaining updated Android security patches may provide indirect protections.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents a clear risk to device availability and system stability. IT and security administrators should prioritize firmware updates from their device manufacturers as soon as Unisoc releases the necessary patches. Until a fix is deployed, ensure that devices are running the latest available OS updates to minimize the attack surface.

More Unisoc CVEs

Sources