Junglewise Threat Intelligence

CVE-2025-71252: Unisoc Modem IMS improper input validation denial of service

CVE-2025-71252 · Severity: high · CVSS 7.5 · Published 2026-05-06

Technologies: Unisoc T7280, Unisoc T310, Unisoc T7225, Unisoc T7255, Unisoc T9100, Unisoc Sc7731e, Unisoc T610, Unisoc T618, Unisoc Sc9863a, Unisoc T8300, Unisoc T7250, Unisoc T7200, Unisoc T8100, Unisoc T8200, Unisoc Sc9832e, Unisoc T7300. Vendors: Unisoc.

Executive brief

A vulnerability exists in the IP Multimedia Subsystem (IMS) component of several Unisoc mobile chipsets. This component is responsible for handling voice and multimedia services over cellular networks. An attacker could exploit this flaw to remotely crash the device's modem, leading to a loss of cellular connectivity and a denial of service for the user.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Unisoc Modem IMS (IP Multimedia Subsystem) component. The flaw allows a remote, unauthenticated attacker to send specially crafted packets over the network to trigger a system crash or modem reset. No user interaction or special execution privileges are required to exploit this vulnerability. The issue affects a wide range of Unisoc chipsets (including SC and T series) running Android versions 13, 14, 15, and 16. Successful exploitation results in a complete denial of service for cellular and multimedia functions.

Affected products

  • Unisoc SC7731E Android 13, 14, 15, 16
  • Unisoc SC9832E Android 13, 14, 15, 16
  • Unisoc SC9863A Android 13, 14, 15, 16
  • Unisoc T310 Android 13, 14, 15, 16
  • Unisoc T610 Android 13, 14, 15, 16
  • Unisoc T618 Android 13, 14, 15, 16
  • Unisoc T7200 Android 13, 14, 15, 16
  • Unisoc T7225 Android 13, 14, 15, 16
  • Unisoc T7250 Android 13, 14, 15, 16
  • Unisoc T7255 Android 13, 14, 15, 16
  • Unisoc T7280 Android 13, 14, 15, 16
  • Unisoc T7300 Android 13, 14, 15, 16
  • Unisoc T8100 Android 13, 14, 15, 16
  • Unisoc T8200 Android 13, 14, 15, 16
  • Unisoc T8300 Android 13, 14, 15, 16
  • Unisoc T9100 Android 13, 14, 15, 16

Timeline

  • 2026-05-06: advisory: Initial advisory published by Unisoc

References

Related threats