Junglewise Threat Intelligence

CVE-2025-71254: Unisoc Modem IMS improper input validation denial of service

CVE-2025-71254 · Severity: high · CVSS 7.5 · Published 2026-05-06

Technologies: Unisoc T7280, Unisoc T310, Unisoc T7225, Unisoc T7255, Unisoc T9100, Unisoc Sc7731e, Unisoc T610, Unisoc T618, Unisoc Sc9863a, Unisoc T8300, Unisoc T7250, Unisoc T7200, Unisoc T8100, Unisoc T8200, Unisoc Sc9832e, Unisoc T7300. Vendors: Unisoc.

Executive brief

A vulnerability exists in the cellular modem software of several Unisoc chipsets used in mobile devices. This component is responsible for handling IP Multimedia Subsystem (IMS) functions like Voice over LTE (VoLTE). An attacker could remotely crash the modem, causing a loss of cellular connectivity and emergency services without any user interaction.

Technical details

A vulnerability in the Modem IMS (IP Multimedia Subsystem) component of multiple Unisoc chipsets is caused by improper input validation (CWE-20). The flaw can be triggered remotely over the network without any authentication or user interaction. Successful exploitation allows an attacker to cause a system crash or a denial of service (DoS) state in the modem. Affected chipsets include various SC and T-series models running Android versions 13 through 16. Users should apply security updates provided by their device manufacturers.

Affected products

  • Unisoc SC7731E Android 13, 14, 15, 16
  • Unisoc SC9832E Android 13, 14, 15, 16
  • Unisoc SC9863A Android 13, 14, 15, 16
  • Unisoc T310 Android 13, 14, 15, 16
  • Unisoc T610 Android 13, 14, 15, 16
  • Unisoc T618 Android 13, 14, 15, 16
  • Unisoc T7200 Android 13, 14, 15, 16
  • Unisoc T7225 Android 13, 14, 15, 16
  • Unisoc T7250 Android 13, 14, 15, 16
  • Unisoc T7255 Android 13, 14, 15, 16
  • Unisoc T7280 Android 13, 14, 15, 16
  • Unisoc T7300 Android 13, 14, 15, 16
  • Unisoc T8100 Android 13, 14, 15, 16
  • Unisoc T8200 Android 13, 14, 15, 16
  • Unisoc T8300 Android 13, 14, 15, 16
  • Unisoc T9100 Android 13, 14, 15, 16

Timeline

  • 2026-05-06: advisory: Initial advisory published by Unisoc

References

Related threats