CVE-2025-61615
7.5Unisoc (Shanghai) Technologies Co., Ltd. · T8100/T9100/T8200/T8300 Modems
A vulnerability in Unisoc NR modems allows for a remote system crash due to improper input validation, leading to a denial of service.
Executive summary
A critical vulnerability in Unisoc modem firmware allows unauthenticated remote attackers to trigger a system crash, resulting in a denial of service.
Vulnerability
The vulnerability stems from improper input validation within the NR modem component, which can be exploited by an unauthenticated remote attacker to cause a system crash.
Business impact
The potential for a remote denial of service poses a significant risk to device availability, particularly for mobile hardware relying on these modem chipsets. With a CVSS score of 7.5, this flaw represents a High severity risk, as it permits attackers to disrupt cellular connectivity and system stability without requiring any user interaction or elevated privileges.
Remediation
Immediate Action: Monitor official communication channels from Unisoc and your device manufacturer for the release of security patches and apply them to affected firmware immediately.
Proactive Monitoring: Review system diagnostic logs for unexpected modem resets or connectivity drops that may indicate exploitation attempts.
Compensating Controls: While specific network-level mitigations are difficult for modem-level flaws, ensure that devices are running the latest security patches provided by the OEM to minimize the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the ability for unauthenticated remote actors to cause system crashes, this vulnerability must be treated with high priority. Organizations and individual users should verify the firmware version of their Unisoc-based devices and apply updates as soon as they are made available by the vendor to prevent potential service disruptions.