Executive brief
A vulnerability exists in the 5G (NR) modem software used in several Unisoc chipsets found in mobile devices. An attacker could remotely exploit this flaw to crash the modem, causing a loss of cellular connectivity and a denial of service. This attack can be carried out over the network without any user interaction or special access permissions.
Technical details
An improper input validation vulnerability (CWE-20) exists in the New Radio (NR) modem component of Unisoc T8100, T9100, T8200, and T8300 chipsets. The flaw allows a remote, unauthenticated attacker to send specially crafted packets over the network to trigger a system crash or modem hang. No additional execution privileges or user interaction are required for exploitation. The vulnerability affects devices running Android versions 13 through 16 using the impacted hardware. A fix is typically distributed via vendor-specific security updates or OEM firmware patches.
Affected products
- Unisoc T8100 chipset Android 13, 14, 15, 16
- Unisoc T9100 chipset Android 13, 14, 15, 16
- Unisoc T8200 chipset Android 13, 14, 15, 16
- Unisoc T8300 chipset Android 13, 14, 15, 16
Timeline
- 2026-05-06: advisory: Initial advisory published by Unisoc
- 2026-05-06: disclosed: NVD publication date