CVE-2026-21548
Unisoc · T8100/T9100/T8200/T8300
A vulnerability in the Unisoc NR modem firmware allows for potential denial of service via improper input validation of network traffic.
Executive summary
A critical input validation vulnerability in Unisoc modem firmware could allow unauthenticated attackers to cause a denial of service on mobile devices.
Vulnerability
This vulnerability, classified as CWE-20, involves improper input validation within the NR modem component. It allows an unauthenticated, remote attacker (AV:N, PR:N) to send specially crafted inputs that trigger a denial of service condition.
Business impact
The ability for a remote attacker to crash the modem component of a mobile device poses a significant risk to availability and connectivity. With a CVSS score of 7.5, the potential for widespread service disruption on affected mobile handsets makes this a high-urgency issue for device manufacturers and telecommunications providers.
Remediation
Immediate Action: Check with the device manufacturer or service provider for firmware updates that include the necessary fixes for the affected Unisoc modem chipsets.
Proactive Monitoring: Monitor device performance and connectivity stability for signs of unexpected modem resets or network service drops.
Compensating Controls: Since this is a hardware-layer vulnerability, there are limited software-based compensating controls; ensuring the device operating system is fully patched is the best defense.
Exploitation status
Public Exploit Available: No confirmed public exploit exists in the available data.
Analyst recommendation
Because this vulnerability affects core modem firmware, it is essential to monitor manufacturer security bulletins for firmware releases. Users should install updates as soon as they are made available by their device vendor to restore stable and secure modem operation.