CVE-2025-69278
7.5Unisoc (Shanghai) Technologies Co., Ltd. · T7300/T8100/T9100/T8200/T8300 Modems
A vulnerability in the nr modem component of Unisoc chipsets allows for a remote system crash due to improper input validation.
Executive summary
A critical input validation flaw in Unisoc modems exposes devices to remote denial of service attacks without requiring user interaction or authentication.
Vulnerability
The vulnerability is an improper input validation flaw (CWE-20) within the nr modem component. It allows an unauthenticated, remote attacker to trigger a system crash, resulting in a denial of service.
Business impact
The ability for a remote attacker to crash mobile device modems can lead to widespread service disruption, rendering devices unable to perform cellular communications. With a CVSS score of 7.5, this high severity vulnerability poses a significant risk to fleet availability and user productivity. Organizations relying on these devices for critical communications may face operational downtime if the vulnerability is leveraged in the wild.
Remediation
Immediate Action: Review the Unisoc support announcement for specific firmware update availability and deploy patches to all affected devices as soon as they are provided by the device manufacturer.
Proactive Monitoring: Monitor device logs for recurring modem restarts or unexpected network connectivity drops that could indicate exploitation attempts.
Compensating Controls: While direct mitigation for modem-level flaws is limited, ensure that devices are running the latest security patch levels provided by the handset vendor to reduce the overall attack surface.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for remote denial of service and the high CVSS rating, security teams should prioritize tracking firmware updates for the affected Unisoc chipsets. Ensure that communication is maintained with device vendors to receive timely security bulletins, as modem-level vulnerabilities often require vendor-specific firmware updates to resolve.