UNISOC Modem Vulnerability Allows Remote Code Execution via Cellular Calls
Article Content
- •Critical vulnerability in UNISOC modem firmware allows remote code execution.
- •Millions of devices from major brands are potentially affected.
- •Exploit demonstrated using specific tools and methods in a controlled environment.
A critical vulnerability in UNISOC modem firmware has been discovered, enabling remote code execution through cellular calls. This flaw affects millions of devices using UNISOC chipsets, including models from Motorola, Samsung, Vivo, and Realme. The vulnerability, classified as CWE-674, arises from improper parsing of message attributes, leading to uncontrolled recursion. Attackers can exploit this by sending specially crafted messages during high-bandwidth operations like video calls, causing a stack overflow and executing arbitrary code. Independent researcher 0x50594d demonstrated the exploit using a controlled environment with tools like Dockerized Open5GS and Kamailio. The affected chipsets include the T612, T616, T606, and T7250 models. As of now, the vulnerability remains unpatched, posing a significant risk to users. UNISOC has been contacted for remediation but has yet to respond.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track SSD Secure Disclosure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…