Junglewise Threat Intelligence

CVE-2025-71251: Unisoc Modem improper input validation in IMS

CVE-2025-71251 · Severity: high · CVSS 7.5 · Published 2026-05-06

Technologies: Unisoc T7280, Unisoc T310, Unisoc T7225, Unisoc T7255, Unisoc T9100, Unisoc Sc7731e, Unisoc T610, Unisoc T618, Unisoc Sc9863a, Unisoc T8300, Unisoc T7250, Unisoc T7200, Unisoc T8100, Unisoc T8200, Unisoc Sc9832e, Unisoc T7300. Vendors: Unisoc.

Executive brief

A vulnerability exists in the modem software of several Unisoc chipsets used in mobile devices. This component handles IP Multimedia Subsystem (IMS) functions, which are responsible for delivering multimedia services like Voice over LTE (VoLTE). An attacker could remotely trigger a system crash, leading to a total loss of cellular connectivity and service availability for the user.

Technical details

A vulnerability classified as improper input validation (CWE-20) exists in the Unisoc Modem IMS (IP Multimedia Subsystem) component. The flaw allows a remote, unauthenticated attacker to send specially crafted network traffic that triggers a system crash. This results in a denial of service (DoS) affecting the device's cellular and multimedia communication capabilities. The vulnerability affects multiple chipsets running Android versions 13 through 16. No additional execution privileges or user interaction are required for exploitation.

Affected products

  • Unisoc SC7731E Android 13, 14, 15, 16
  • Unisoc SC9832E Android 13, 14, 15, 16
  • Unisoc SC9863A Android 13, 14, 15, 16
  • Unisoc T310 Android 13, 14, 15, 16
  • Unisoc T610 Android 13, 14, 15, 16
  • Unisoc T618 Android 13, 14, 15, 16
  • Unisoc T7200 Android 13, 14, 15, 16
  • Unisoc T7225 Android 13, 14, 15, 16
  • Unisoc T7250 Android 13, 14, 15, 16
  • Unisoc T7255 Android 13, 14, 15, 16
  • Unisoc T7280 Android 13, 14, 15, 16
  • Unisoc T7300 Android 13, 14, 15, 16
  • Unisoc T8100 Android 13, 14, 15, 16
  • Unisoc T8200 Android 13, 14, 15, 16
  • Unisoc T8300 Android 13, 14, 15, 16
  • Unisoc T9100 Android 13, 14, 15, 16

Timeline

  • 2026-05-06: advisory: Initial advisory published by Unisoc
  • 2026-05-06: disclosed: CVE published to NVD

References

Related threats