CVE-2025-61619
7.5Unisoc (Shanghai) Technologies Co., Ltd. · T8100/T9100/T8200/T8300 Modems
A vulnerability in Unisoc NR modems allows unauthenticated remote attackers to trigger a system crash via improper input validation, resulting in a denial of service.
Executive summary
A critical denial of service vulnerability in Unisoc modem firmware allows unauthenticated remote attackers to crash affected mobile devices.
Vulnerability
This flaw exists due to improper input validation within the NR modem component. It permits an unauthenticated attacker to remotely cause a system crash, effectively resulting in a denial of service.
Business impact
Successful exploitation of this vulnerability results in a denial of service, rendering the affected mobile device unresponsive or forcing a reboot. Given the CVSS score of 7.5, the impact is significant for users relying on these devices for critical communication, as it allows remote disruption of service without requiring prior authentication or user interaction.
Remediation
Immediate Action: Monitor the official Unisoc support portal for firmware updates and apply them to all affected devices as soon as they become available.
Proactive Monitoring: Security teams should monitor device logs for unexpected system restarts or modem service errors that may indicate exploitation attempts.
Compensating Controls: While direct mitigation is limited for modem-level flaws, maintaining updated mobile operating systems and utilizing network-level protections may reduce the overall attack surface.
Exploitation status
Public Exploit Available: No — exploit_available (unknown).
Analyst recommendation
This vulnerability presents a high risk to mobile device availability due to the lack of required authentication. Organizations using devices equipped with the specified Unisoc modems must prioritize the deployment of vendor-supplied firmware updates to resolve the underlying input validation error and prevent potential remote service disruption.