CVE-2026-21549

Unisoc · T8100/T9100/T8200/T8300

A vulnerability in the Unisoc modem firmware allows for improper input validation, potentially leading to a denial of service condition.

Executive summary

A high-severity input validation flaw in Unisoc modem firmware, affecting multiple Android versions, presents a significant risk of remote denial of service.

Vulnerability

This vulnerability is caused by improper input validation within the modem component. As indicated by the CVSS vector (AV:N/PR:N/UI:N), the flaw is remotely exploitable by an unauthenticated attacker.

Business impact

The exploitation of this vulnerability results in a denial of service condition, which can lead to critical system instability or total loss of modem functionality. Given the CVSS score of 7.5, this high-severity issue impacts mobile device availability and reliability, potentially hindering business-critical communications.

Remediation

Immediate Action: Monitor the official Unisoc product security bulletin for the release of firmware updates and apply them to affected devices as soon as they become available.

Proactive Monitoring: Security teams should monitor device logs for unexpected modem resets or connectivity drops that could indicate exploitation attempts.

Compensating Controls: While specific network-level controls are difficult for modem-level flaws, ensure that devices are managed through a Mobile Device Management (MDM) solution to enforce security policies and expedite patch deployment.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the remote exploitability and the critical role of the modem in mobile device operations, this vulnerability poses a significant availability risk. Organizations should prioritize patching as soon as the vendor provides the necessary firmware updates to ensure device stability and continuity of service.