Junglewise Threat Intelligence

CVE-2025-71255: Unisoc Modem IMS improper input validation denial of service

CVE-2025-71255 · Severity: high · CVSS 7.5 · Published 2026-05-06

Technologies: Unisoc T7280, Unisoc T310, Unisoc T7225, Unisoc T7255, Unisoc T9100, Unisoc Sc7731e, Unisoc T610, Unisoc T618, Unisoc Sc9863a, Unisoc T8300, Unisoc T7250, Unisoc T7200, Unisoc T8100, Unisoc T8200, Unisoc Sc9832e, Unisoc T7300. Vendors: Unisoc.

Executive brief

A vulnerability exists in the modem software of several Unisoc chipsets used in mobile devices. This component handles IP Multimedia Subsystem (IMS) functions, which are responsible for modern voice and data communication. An attacker could remotely crash the modem, causing a complete loss of cellular connectivity and emergency services without any user interaction.

Technical details

The vulnerability is classified as CWE-20 (Improper Input Validation) within the Modem IMS (IP Multimedia Subsystem) component of various Unisoc chipsets. The flaw allows a remote attacker to send specially crafted network traffic that the modem fails to validate correctly, leading to a system crash. This results in a Denial of Service (DoS) condition affecting cellular services. The attack vector is network-based, requires no authentication (PR:N), and no user interaction (UI:N). Affected chipsets include a wide range of Unisoc models (SC and T series) running Android versions 13 through 16.

Affected products

  • Unisoc SC7731E Android 13, 14, 15, 16
  • Unisoc SC9832E Android 13, 14, 15, 16
  • Unisoc SC9863A Android 13, 14, 15, 16
  • Unisoc T310 Android 13, 14, 15, 16
  • Unisoc T610/T618 Android 13, 14, 15, 16
  • Unisoc T7200/T7225/T7250/T7255/T7280/T7300 Android 13, 14, 15, 16
  • Unisoc T8100/T8200/T8300/T9100 Android 13, 14, 15, 16

Timeline

  • 2026-05-06: advisory: Initial advisory published by Unisoc
  • 2026-05-06: disclosed: CVE published to NVD

References

Related threats