PatchSiren cyber security CVE debrief
CVE-2025-71253 Unisoc CVE debrief
CVE-2025-71253 is a High-severity denial-of-service issue reported in Unisoc Modem IMS. According to the CVE description, improper input validation could let a remote attacker disrupt service without needing execution privileges. NVD rates the issue 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), which points to a network-reachable availability impact rather than data theft or code execution. NVD also links to a Unisoc vendor advisory, and the affected platform entries include Android 13 through Android 16.
- Vendor
- Unisoc
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-06
- Original CVE updated
- 2026-07-25
- Advisory published
- 2026-05-06
- Advisory updated
- 2026-07-25
Who should care
Security teams and device operators responsible for Android systems that include Unisoc modem/IMS components, especially where the device firmware tracks the Android 13, 14, 15, or 16 CPE entries listed by NVD. Managed fleets, mobile carriers, OEMs, and incident responders should prioritize validation of vendor bulletin guidance and firmware status.
Technical summary
The available evidence describes an improper input validation flaw in Modem IMS. The stated impact is remote denial of service with no additional execution privileges needed. NVD’s CVSS vector indicates a network attack path with low complexity, no privileges, no user interaction, and high availability impact only. NVD’s weakness metadata is generic (NVD-CWE-noinfo), so the specific validation failure mode is not identified in the supplied corpus.
Defensive priority
High. The CVSS score is 7.5 and the issue is remotely reachable, unauthenticated, and availability-impacting. For mobile and carrier-managed environments, service disruption on modem/IMS paths can be operationally significant even without confidentiality or integrity impact.
Recommended defensive actions
- Review the Unisoc vendor advisory referenced by NVD and confirm whether your firmware build includes the affected Modem IMS component.
- Inventory Android 13/14/15/16 devices in scope and map them to the vendor's affected software or firmware releases.
- Apply vendor firmware updates or carrier/OEM remediation guidance as soon as available.
- Monitor for unexpected modem/IMS instability, crash loops, or repeated service interruptions on affected devices.
- If patching is delayed, isolate or segment high-value devices where feasible and increase operational monitoring for availability degradation.
Evidence notes
All substantive claims in this debrief are grounded in the supplied NVD record and its linked Unisoc vendor advisory reference. The CVE description states improper input validation in Modem IMS leading to remote denial of service with no additional execution privileges. NVD classifies the issue as CVSS 7.5 HIGH, vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, and records affected Android 13-16 CPE entries plus a vendor advisory reference. No exploit details, proof-of-concept, or unverified product-specific remediation steps are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-71253 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-71253
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-71253 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-71253
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.unisoc.com/en/support/product-security-bulletin/2051836844671422466
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.