Skip to content
UNISOC Modem Vulnerability Allows Remote Code Execution via Cellular Calls

UNISOC Modem Vulnerability Allows Remote Code Execution via Cellular Calls

First seen 22 Mar 2026, 12:43 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 22, 2026 at 22:28 UTC
  • Critical vulnerability in UNISOC modem firmware allows remote code execution.
  • Millions of devices from major brands are potentially affected.
  • Exploit demonstrated using specific tools and methods in a controlled environment.

A critical vulnerability in UNISOC modem firmware has been discovered, enabling remote code execution through cellular calls. This flaw affects millions of devices using UNISOC chipsets, including models from Motorola, Samsung, Vivo, and Realme. The vulnerability, classified as CWE-674, arises from improper parsing of message attributes, leading to uncontrolled recursion. Attackers can exploit this by sending specially crafted messages during high-bandwidth operations like video calls, causing a stack overflow and executing arbitrary code. Independent researcher 0x50594d demonstrated the exploit using a controlled environment with tools like Dockerized Open5GS and Kamailio. The affected chipsets include the T612, T616, T606, and T7250 models. As of now, the vulnerability remains unpatched, posing a significant risk to users. UNISOC has been contacted for remediation but has yet to respond.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 181d ago How this analysis works

Timeline

2026-03-20
Gbhackers article published detailing the vulnerability.
2026-03-22
Linkedin article published with exploit demonstration.
Date unknown
UNISOC contacted for remediation.

More articles in this cluster (2)

Following this threat?

Track SSD Secure Disclosure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed