Description
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Published: 2026-08-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper input validation flaw in the modem firmware of Unisoc UDX710 devices that can lead to remote denial of service. The flaw allows an attacker to send malformed or malicious input that causes the modem to crash or reset, interrupting network services. The attack vector is not explicitly stated, but based on the description it is inferred that the flaw is exploitable through a remote interface that accepts user‑supplied data.

Affected Systems

Affected devices are Unisoc (Shanghai) Technologies Co., Ltd. modem devices running the UDX710 firmware. Specific firmware versions are not listed in the vulnerability report, so the impact applies to all versions of the UDX710 that contain the unpatched code.

Risk and Exploitability

The CVSS base score of 7.5 indicates a high-level severity, and the EPSS score of 0.00403 indicates a very low probability of exploitation. The vulnerability is not included in the CISA KEV catalog. Exploitation appears to require remote access to the modem's input interface; no additional privileges are needed, making it easier to target. Because the flaw directly disrupts service availability, the risk to organizations that rely on the impacted modems includes service downtime and potential cascading effects on dependent systems. While no publicly disclosed exploits are known, the high severity warrants timely patching or mitigation.

Generated by OpenCVE AI on August 4, 2026 at 21:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied firmware update that addresses the improper input validation flaw
  • Disable or restrict remote configuration interfaces on the modem to limit exposure to trusted management networks
  • Implement network segmentation or firewall rules to control traffic to the modem's control ports, allowing only authorized IP addresses to communicate
  • Monitor modem logs and restart events for abnormal activity and consider rate‑limiting accepted input

Generated by OpenCVE AI on August 4, 2026 at 21:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Unisoc
Unisoc udx710
Vendors & Products Unisoc
Unisoc udx710

Tue, 04 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Unisoc UDX710 Modem Causing Remote Denial of Service

Mon, 03 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Description In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Unisoc

Published:

Updated: 2026-08-03T11:25:18.161Z

Reserved: 2025-12-31T07:33:23.121Z

Link: CVE-2026-21555

cve-icon Vulnrichment

Updated: 2026-08-03T11:25:14.592Z

cve-icon NVD

Status : Received

Published: 2026-08-03T08:17:20.257

Modified: 2026-08-03T13:17:19.083

Link: CVE-2026-21555

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T12:01:54Z

Weaknesses
  • CWE-20

    Improper Input Validation