CVE-2025-61618

7.5

Unisoc · NR Modem (T8100/T9100/T8200/T8300)

An improper input validation vulnerability in the Unisoc NR modem allows unauthenticated remote attackers to trigger a system crash, resulting in a denial of service.

Executive summary

A critical vulnerability in Unisoc NR modems allows remote, unauthenticated attackers to cause a system crash, resulting in a denial of service.

Vulnerability

This flaw stems from improper input validation (CWE-20) within the NR modem firmware. An unauthenticated remote attacker can supply malicious input to the modem, leading to a system-wide denial of service without requiring any user interaction or elevated privileges.

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high severity due to the potential for remote exploitation without authentication. Successful exploitation results in a complete loss of modem availability, which effectively disconnects affected devices from cellular networks, causing significant operational disruption and loss of communication for end users.

Remediation

Immediate Action: Consult the official Unisoc support announcement and apply the latest firmware updates as soon as they are made available by your device manufacturer.

Proactive Monitoring: Monitor device logs for recurring modem reset events or unexpected system reboots that may indicate exploitation attempts.

Compensating Controls: While network-level mitigations are difficult for modem-specific flaws, ensure devices are protected by robust device management policies and avoid connecting to untrusted cellular or radio environments where possible.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the remote nature of this vulnerability and the lack of required authentication, organizations using devices with Unisoc T-series modems should treat this as a high-priority risk. Administrators must track vendor-specific security bulletins for their device manufacturers and deploy patches immediately upon release to prevent potential denial of service attacks.

More Unisoc CVEs

Sources