Junglewise Threat Intelligence

CVE-2025-71256: Unisoc NR modem improper input validation in T8000/T9000 series chipsets

CVE-2025-71256 · Severity: high · CVSS 7.5 · Published 2026-05-06

Technologies: Unisoc T9100, Unisoc T8300, Unisoc T8100, Unisoc T8200. Vendors: Unisoc.

Executive brief

A vulnerability exists in the 5G (NR) modem software used in several Unisoc chipsets found in mobile devices. An attacker could remotely exploit this flaw to crash the modem, causing a loss of cellular connectivity and a denial of service. This attack can be carried out over the network without any user interaction or special access permissions.

Technical details

An improper input validation vulnerability (CWE-20) exists in the New Radio (NR) modem component of Unisoc T8100, T9100, T8200, and T8300 chipsets. The flaw allows a remote, unauthenticated attacker to send specially crafted packets over the network to trigger a system crash or modem hang. No additional execution privileges or user interaction are required for exploitation. The vulnerability affects devices running Android versions 13 through 16 using the impacted hardware. A fix is typically distributed via vendor-specific security updates or OEM firmware patches.

Affected products

  • Unisoc T8100 chipset Android 13, 14, 15, 16
  • Unisoc T9100 chipset Android 13, 14, 15, 16
  • Unisoc T8200 chipset Android 13, 14, 15, 16
  • Unisoc T8300 chipset Android 13, 14, 15, 16

Timeline

  • 2026-05-06: advisory: Initial advisory published by Unisoc
  • 2026-05-06: disclosed: NVD publication date

References

Related threats