CVE-2026-21552

Unisoc · T8100/T9100/T8200/T8300

An improper input validation vulnerability exists in the Unisoc modem firmware, potentially allowing for denial of service conditions.

Executive summary

A high-severity input validation flaw in the Unisoc modem firmware on various Android versions poses a significant risk of service disruption.

Vulnerability

This vulnerability involves improper input validation within the modem component. Based on the CVSS vector (AV:N/AC:L/PR:N/UI:N), the flaw is remotely exploitable by an unauthenticated attacker.

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high risk to availability. Successful exploitation could lead to modem crashes or complete loss of cellular connectivity, resulting in significant downtime for mobile devices or critical communication infrastructure.

Remediation

Immediate Action: Monitor the official Unisoc support portal for security updates and apply them to affected devices as soon as they become available.

Proactive Monitoring: Security teams should monitor device logs for unexpected modem restarts or connectivity drops that may indicate exploitation attempts.

Compensating Controls: Ensure devices are running the latest security patches provided by the device manufacturer, as these often bundle firmware updates from chipset vendors.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for remote denial of service, administrators must prioritize this vulnerability. Organizations should track the release of updated firmware through the Unisoc support channel and coordinate an accelerated deployment schedule once the patch is confirmed.