Description
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Published: 2026-08-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from an improper input validation in the Unisoc UDX710 modem, allowing crafted inputs to be processed without proper checks. This flaw can cause the modem to crash or become unresponsive, effectively denying service to legitimate users. The primary impact is a disruption of network connectivity and associated services, with no need for elevated privileges to exploit the weakness.

Affected Systems

Vendors impacted are Unisoc (Shanghai) Technologies Co., Ltd., specifically the UDX710 modem. No version details are provided in the data, so all current UDX710 devices should be considered vulnerable until a patch is released.

Risk and Exploitability

The vulnerability scores a CVSS of 7.5, indicating a high severity level. The EPSS score is very low (<1%), suggesting that exploitation is not widely observed, but the flaw remains significant due to its high impact. The issue is not listed in CISA’s KEV catalog. The likely attack vector is remote, achieved by sending malformed or oversized inputs over the network interface that the modem exposes. No additional execution privileges are required, meaning an attacker could trigger a denial of service from distance without compromising the host.

Generated by OpenCVE AI on August 4, 2026 at 21:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑released firmware or security patch for the Unisoc UDX710 modem as soon as it becomes available
  • If a patch is not yet released, upgrade the modem to the latest firmware version offered by Unisoc, which may contain mitigation improvements
  • Configure network segmentation or firewall rules to limit external access to the modem’s management interfaces, reducing exposure to malformed input attempts
  • Monitor modem logs and performance metrics for signs of repeated crashes or abnormal traffic patterns to detect early exploitation attempts

Generated by OpenCVE AI on August 4, 2026 at 21:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Unisoc
Unisoc udx710
Vendors & Products Unisoc
Unisoc udx710

Tue, 04 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Unisoc UDX710 Modem Leading to Remote Denial of Service

Mon, 03 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Description In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Unisoc

Published:

Updated: 2026-08-03T11:25:46.974Z

Reserved: 2025-12-31T07:33:23.121Z

Link: CVE-2026-21554

cve-icon Vulnrichment

Updated: 2026-08-03T11:25:42.943Z

cve-icon NVD

Status : Received

Published: 2026-08-03T08:17:20.130

Modified: 2026-08-03T13:17:18.970

Link: CVE-2026-21554

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T12:01:55Z

Weaknesses
  • CWE-20

    Improper Input Validation