PT-2025-41625 · Unisoc · Unisoc Modem
CVE-2025-31718
·
Published
2025-10-11
·
Updated
2026-08-18
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Unisoc modem firmware (affected versions not specified)
Description
Improper input validation within the modem processing routines can lead to a system crash. This flaw allows for remote escalation of privilege, enabling an attacker to execute arbitrary code or commands with elevated privileges and potentially compromise the entire device. In specific scenarios involving Unisoc chipsets (such as T606, T612, and T7250), this can be part of an exploit chain where an attacker controlling a private 4G network sends a maliciously crafted VoLTE SIP video call. If the victim answers, the attacker can write a full-access configuration to the modem's ARM memory protection unit via coprocessor registers. This maps the entire 32-bit physical address space as readable, writable, and executable from the modem context, including pages containing the Android kernel, due to a lack of hardware restrictions between the modem processor and the application processor within the SoC.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Unisoc Modem