CVE-2025-61616

7.5

Unisoc (Shanghai) Technologies Co., Ltd. · T8100, T9100, T8200, T8300 NR Modem

A vulnerability in the Unisoc NR modem allows unauthenticated remote attackers to trigger a system crash via improper input validation, resulting in a denial of service.

Executive summary

A critical vulnerability in the Unisoc NR modem firmware allows unauthenticated attackers to cause a remote system crash, posing a significant risk to device availability.

Vulnerability

This flaw involves improper input validation (CWE-20) within the NR modem component. An unauthenticated attacker can trigger this condition remotely to achieve a denial of service state, requiring no elevated privileges.

Business impact

The ability for an unauthenticated attacker to remotely crash the modem component directly impacts the availability and reliability of affected mobile devices. Given the CVSS score of 7.5, this high-severity issue could lead to widespread service disruption, hindering communication capabilities and potentially impacting business operations that rely on these mobile platforms.

Remediation

Immediate Action: Consult the official Unisoc support portal to identify and apply the latest firmware security updates provided by your specific device manufacturer.

Proactive Monitoring: Monitor device performance for unexpected reboots or modem connectivity failures, and review system logs for recurring errors related to radio interface layer (RIL) service crashes.

Compensating Controls: While direct mitigation requires firmware updates, organizations should enforce network security policies that restrict untrusted traffic from reaching mobile baseband interfaces where possible.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents a clear risk to device stability and service uptime due to the lack of required authentication. It is imperative that administrators and users verify their firmware versions against the vendor advisory and deploy the necessary patches immediately upon release by their device vendor.

More Unisoc (Shanghai) Technologies Co., Ltd. CVEs

Sources