Impact
A flaw in the modem software enables an attacker to send crafted input that is not properly validated, causing the modem to become unresponsive. The vulnerability does not grant the attacker any privileges beyond original access, but it can disrupt network connectivity for the affected device.
Affected Systems
Unisoc (Shanghai) Technologies Co., Ltd. devices based on the T8100, T9100, T8200, and T8300 series. No specific firmware or software versions were disclosed, so all current releases for these models should be considered vulnerable until a vendor update is available.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score is <1%, indicating a very low exploitation probability. The vulnerability is not in CISA’s KEV catalog. The likely attack vector is remote; an attacker can trigger the denial of service by sending malformed data over the modem’s control interface without requiring additional privileges.
OpenCVE Enrichment