Description
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Published: 2026-08-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the modem’s input handling and can be triggered remotely without any privilege escalation. It is caused by improper input validation, which falls under CWE-20. An attacker that can reach the modem over the network can send malformed data that causes the hardware or firmware to crash or reboot, thereby denying legitimate users connectivity and availability. Because no additional privileges are required, even unauthenticated users could abuse the flaw. The installation of an unpatched firmware is sufficient to expose the device to this risk.

Affected Systems

The products affected are Unisoc (Shanghai) Technologies Co., Ltd.’s modem series, including the T8100, T9100, T8200, and T8300 models. No specific firmware versions are listed, so all builds within these series are potentially affected.

Risk and Exploitability

The CVSS score of 7.5 indicates a high‑to‑critical severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, but a flaw of this type can still be exploited if the device is exposed to an untrusted network. The malicious payload can be delivered through normal data channels used by the modem, and because no authentication or elevated privileges are required, the attack vector is likely remote. While no public exploit code has been reported, the combination of high severity and remote reachability warrants swift remediation if possible.

Generated by OpenCVE AI on August 4, 2026 at 21:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Unisoc’s support portal or supplier for an available firmware update that addresses the input validation issue
  • Apply the vendor‑issued firmware update or patch as soon as it becomes available
  • If a patch is not immediately available, isolate the modem from untrusted networks and monitor system logs for sudden resets or crashes
  • Maintain up‑to‑date inventory of affected models to ensure that future updates can be deployed quickly

Generated by OpenCVE AI on August 4, 2026 at 21:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Unisoc
Unisoc t8100
Unisoc t8200
Unisoc t8300
Unisoc t9100
Vendors & Products Unisoc
Unisoc t8100
Unisoc t8200
Unisoc t8300
Unisoc t9100

Tue, 04 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Improper Input Validation Leading to Remote Denial of Service in Unisoc Modem

Mon, 03 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Description In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Unisoc

Published:

Updated: 2026-08-03T14:20:00.450Z

Reserved: 2025-12-31T07:33:23.120Z

Link: CVE-2026-21552

cve-icon Vulnrichment

Updated: 2026-08-03T14:19:55.605Z

cve-icon NVD

Status : Received

Published: 2026-08-03T08:17:19.903

Modified: 2026-08-03T15:16:19.210

Link: CVE-2026-21552

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T12:01:58Z

Weaknesses
  • CWE-20

    Improper Input Validation