CVE-2025-69279

7.5

Unisoc (Shanghai) Technologies Co., Ltd. · T8100/T9100/T8200/T8300 Modems

A vulnerability in the Unisoc nr modem allows for a remote denial of service via improper input validation, leading to a potential system crash without requiring user privileges.

Executive summary

A critical input validation flaw in Unisoc modems allows unauthenticated remote attackers to trigger a system crash, resulting in a denial of service.

Vulnerability

This vulnerability is caused by improper input validation (CWE-20) within the nr modem component. An unauthenticated attacker can exploit this remotely to force a system crash, effectively denying service to the affected device.

Business impact

Successful exploitation of this vulnerability results in a total loss of availability for the affected mobile device or hardware. Given the CVSS score of 7.5, the risk is high because the attack vector is network-based and requires no authentication or user interaction, making it highly automatable. This could lead to widespread service disruption for users relying on these modems for critical connectivity.

Remediation

Immediate Action: Monitor the Unisoc support portal for specific firmware patch releases and apply them to all affected devices as soon as they become available.

Proactive Monitoring: Review device logs for unusual modem activity or unexpected service interruptions that may indicate a crash event.

Compensating Controls: While specific network-level controls are difficult for modem-level flaws, ensure that devices are operating within trusted network segments where possible to limit exposure to malicious traffic.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents a significant risk to device stability due to its potential for remote exploitation without authentication. Security teams should prioritize tracking vendor updates for the T8100 through T8300 modem series. Immediate application of forthcoming patches is essential to prevent potential denial of service attacks against these communication components.

More Unisoc (Shanghai) Technologies Co., Ltd. CVEs

Sources