CVE-2026-21553

7.5

Unisoc · T8100/T9100/T8200/T8300

A vulnerability in the Unisoc modem firmware allows for improper input validation, which may lead to system instability or denial of service.

Executive summary

A high-severity input validation vulnerability in Unisoc modem firmware affects devices running Android 13 through 16, creating a risk of service disruption.

Vulnerability

The modem component fails to properly validate input, which could be leveraged by an unauthenticated attacker. This represents a high-severity flaw impacting the availability of the affected modem hardware.

Business impact

With a CVSS score of 7.5, this vulnerability presents a serious risk to operational continuity. Unauthorized parties could trigger a denial of service on the modem, causing loss of network access and potentially impacting critical business functions dependent on cellular connectivity.

Remediation

Immediate Action: Periodically check the Unisoc product security bulletin for the release of firmware patches and deploy them through the standard device management lifecycle.

Proactive Monitoring: Review system logs for signs of abnormal modem behavior or repeated service failures.

Compensating Controls: Restrict unnecessary network exposure where possible, though the nature of modem firmware often limits the effectiveness of traditional network-level controls.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Security teams should treat this as a high-priority item for mobile device fleets. Maintain communication with the device manufacturer to ensure that security updates provided by Unisoc are integrated into the monthly security patch cycle.

More Unisoc CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section