Description
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Published: 2026-08-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The bug is an input validation flaw inside the modem firmware that can be triggered by an attacker who sends specially crafted data to the modem. The flaw does not require privilege escalation; it merely causes the modem to crash or stall, resulting in a loss of network connectivity for the device. Because the crash disables the modem, any services or communications that depend on it are also disrupted.

Affected Systems

This vulnerability applies to all Unisoc (Shanghai) Technologies Co., Ltd. modem devices in the T8100, T9100, T8200, and T8300 series. No specific firmware version is known, so any firmware image running on those units should be considered at risk until a patch is applied.

Risk and Exploitability

With a CVSS score of 7.5 the vulnerability falls into the high severity range. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild, and the absence from the CISA KEV catalog means no publicly known exploits are yet confirmed. The attack vector is most likely remote, over network traffic directed to the modem, exploiting the improper input validation. An attacker would simply send the malicious payload; any host with an older firmware would exhibit service interruption.

Generated by OpenCVE AI on August 4, 2026 at 21:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest firmware version that addresses the input validation flaw from Unisoc’s support site.
  • Contact Unisoc support to confirm that the current firmware is known to contain the fix and to report any other necessary configuration changes.
  • Apply firewall or IDS rules to filter or block abnormal traffic patterns expected to trigger the crash, and monitor for signs of DoS attempts.

Generated by OpenCVE AI on August 4, 2026 at 21:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Unisoc
Unisoc t8100
Unisoc t8200
Unisoc t8300
Unisoc t9100
Vendors & Products Unisoc
Unisoc t8100
Unisoc t8200
Unisoc t8300
Unisoc t9100

Tue, 04 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Improper Input Validation in Unisoc Modem Firmware

Mon, 03 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Description In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Unisoc

Published:

Updated: 2026-08-03T14:24:16.106Z

Reserved: 2025-12-31T07:33:23.120Z

Link: CVE-2026-21550

cve-icon Vulnrichment

Updated: 2026-08-03T14:21:35.692Z

cve-icon NVD

Status : Received

Published: 2026-08-03T08:17:19.663

Modified: 2026-08-03T15:16:18.980

Link: CVE-2026-21550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T12:02:01Z

Weaknesses
  • CWE-20

    Improper Input Validation