CVE-2025-61617
7.5Unisoc (Shanghai) Technologies Co., Ltd. · T8100, T9100, T8200, T8300 Modem
A remote denial of service vulnerability in the Unisoc modem firmware allows unauthenticated attackers to cause a system crash via improper input validation.
Executive summary
A critical vulnerability in Unisoc modems allows unauthenticated remote attackers to trigger a system crash, resulting in a denial of service.
Vulnerability
The vulnerability stems from improper input validation within the modem firmware, which can be exploited by an unauthenticated attacker to induce a system crash. The attack vector is network based and requires no user interaction or elevated privileges to execute.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk. Successful exploitation results in a complete loss of device availability, which can disrupt critical communications and services dependent on the affected mobile hardware. This denial of service capability poses a significant operational risk to users of the impacted hardware.
Remediation
Immediate Action: Monitor the official Unisoc support portal for firmware updates and apply them to all affected devices as soon as they become available.
Proactive Monitoring: Security teams should monitor device logs for unexpected modem resets or network connectivity interruptions that may indicate exploitation attempts.
Compensating Controls: While direct mitigation is limited for modem firmware, ensure that device firewalls and network security policies are configured to block unauthorized traffic directed at mobile telephony components.
Exploitation status
Public Exploit Available: No — exploit_available is unknown.
Analyst recommendation
Given the potential for remote denial of service on mobile hardware, organizations relying on devices utilizing Unisoc T8100, T9100, T8200, or T8300 modems must prioritize this vulnerability. Administrators should maintain close contact with their device manufacturers to receive and deploy the necessary firmware patches as soon as they are released to restore system stability and security.