Description
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Published: 2026-08-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper input validation within the modem firmware. The flaw allows an attacker to craft malformed data that, when processed, causes the modem to become unresponsive. This results in a loss of service availability without requiring any privileged access. The impact is limited to the affected device’s availability rather than confidentiality or integrity.

Affected Systems

Unisoc (Shanghai) Technologies Co., Ltd. exposes the issue in its T8100, T9100, T8200, and T8300 modem families. No specific firmware version data are listed, so any device using these chipsets is potentially affected until a patch is applied.

Risk and Exploitability

The CVSS score of 7.5 indicates a high risk of disruption. The EPSS score of < 1% indicates that the probability of exploitation is low, but the lack of privilege escalation and the potential for remote exploitation suggest that an attacker with network access can trigger the denial of service by sending carefully crafted packets. The vulnerability is not yet listed in the CISA KEV catalog, but its availability impact warrants prompt mitigation.

Generated by OpenCVE AI on August 4, 2026 at 21:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by Unisoc for the affected modem families
  • Configure network firewalls or ACLs to block or rate‑limit malformed traffic that matches known patterns targeting the vulnerability
  • Continuously monitor device logs for repeated failed connections and adjust filtering rules accordingly

Generated by OpenCVE AI on August 4, 2026 at 21:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Unisoc
Unisoc t8100
Unisoc t8200
Unisoc t8300
Unisoc t9100
Vendors & Products Unisoc
Unisoc t8100
Unisoc t8200
Unisoc t8300
Unisoc t9100

Tue, 04 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Unisoc Modem Leading to Remote Denial of Service

Mon, 03 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Description In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Unisoc

Published:

Updated: 2026-08-03T14:19:08.357Z

Reserved: 2025-12-31T07:33:23.121Z

Link: CVE-2026-21553

cve-icon Vulnrichment

Updated: 2026-08-03T14:19:02.738Z

cve-icon NVD

Status : Received

Published: 2026-08-03T08:17:20.020

Modified: 2026-08-03T15:16:19.417

Link: CVE-2026-21553

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T12:01:57Z

Weaknesses
  • CWE-20

    Improper Input Validation