Description
In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed.
Published: 2026-08-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A misuse of input validation is present in the nr modem component, which could allow a remote attacker to trigger a service crash. Based on the description, it is inferred that the attacker would need to perform actions with system execution privileges, enabling abuse of the modem to deny service to legitimate users. The weakness is a classic improper input validation scenario.

Affected Systems

Unisoc (Shanghai) Technologies Co., Ltd. devices bearing the model identifiers T8100, T9100, T8200, and T8300 are impacted. No specific firmware releases were enumerated, so any exposed instance of the nr modem on these platforms is considered vulnerable.

Risk and Exploitability

The CVSS score of 7.5 designates a high severity vulnerability. The EPSS score is 0.00403, indicating a very low but nonzero exploitation probability. The lack of inclusion in CISA’s KEV catalog suggests no publicly known active exploitation yet. Based on the description, it is inferred that the prerequisite of system execution privileges indicates that the attack would likely require either local access or successful privilege escalation on the target device. Based on the description, it is inferred that an attacker could exploit the modem’s interface by injecting malformed data to cause a crash, which would disable services.

Generated by OpenCVE AI on August 4, 2026 at 22:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for a firmware update from Unisoc that addresses this issue.
  • Enforce strict input validation on modem interfaces to mitigate the improper input validation flaw.
  • Restrict modem access to trusted networks only, limiting exposure.

Generated by OpenCVE AI on August 4, 2026 at 22:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Unisoc
Unisoc t8100
Unisoc t8200
Unisoc t8300
Unisoc t9100
Vendors & Products Unisoc
Unisoc t8100
Unisoc t8200
Unisoc t8300
Unisoc t9100

Tue, 04 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Input Validation in Unisoc Modem

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Description In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed.
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Unisoc

Published:

Updated: 2026-08-03T14:27:38.464Z

Reserved: 2025-12-31T07:33:23.119Z

Link: CVE-2026-21548

cve-icon Vulnrichment

Updated: 2026-08-03T14:27:32.585Z

cve-icon NVD

Status : Received

Published: 2026-08-03T08:17:19.393

Modified: 2026-08-03T16:16:29.210

Link: CVE-2026-21548

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T12:02:05Z

Weaknesses
  • CWE-20

    Improper Input Validation