Unisoc is a mobile system-on-chip (SoC) vendor whose products power a broad range of smartphones and embedded devices, particularly in mid-range and emerging-market segments; its disclosure footprint reflects the complexity of firmware and baseband components that integrate multiple memory-intensive subsystems. The vendor's vulnerability portfolio concentrates in its core SoC product lines, including the SC9863A, T610, T618, T606, and T612, and recurs through weakness classes centered on memory-safety boundaries—out-of-bounds writes and reads, buffer overflows, and missing authorization controls in firmware layers. These patterns are structural to the firmware and drivers embedded in low-level device operation, where validation gaps can affect multiple vendors' derivative products and affect the security of millions of downstream deployments. Defenders should track Unisoc SoC disclosures closely when evaluating device firmware and coordinate updates through OEM release cycles, since remediation typically requires vendor integration and device-specific builds. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unisoc (Shanghai) Technologies Co., Ltd. over time
Of all the CVEs published by Unisoc (Shanghai) Technologies Co., Ltd. as a CNA, 97.7% affect products that Unisoc (Shanghai) Technologies Co., Ltd. develops as a vendor.
Of all the CVEs published that affect products developed by Unisoc (Shanghai) Technologies Co., Ltd., 99.7% are self-published by Unisoc (Shanghai) Technologies Co., Ltd. as a CNA.
Signals from CVEs in this vendor scope (635 CVEs).
635 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-71254HIGH In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. | May 6, 2026 | 7.5 | 33 | NO | NO |
CVE-2025-71252HIGH In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. | May 6, 2026 | 7.5 | 33 | NO | NO |
CVE-2025-71255HIGH In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. | May 6, 2026 | 7.5 | 32 | NO | NO |
CVE-2022-27250CRITICAL The UNISOC chipset through 2022-03-15 allows attackers to obtain remote control of a mobile phone, e.g., to obtain sensitive information from text messages or the device's screen, | Mar 18, 2022 | 9.8 | 32 | NO | NO |
CVE-2025-71256HIGH In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. | May 6, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-71253HIGH In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. | May 6, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-71251HIGH In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. | May 6, 2026 | 7.5 | 30 | NO | NO |
CVE-2018-21054CRITICAL An issue was discovered on Samsung mobile devices with M(6.0), N(7.x) and O(8.x) except exynos9610/9820 in all Platforms, M(6.0) except MSM8909 SC77xx/9830 exynos3470/5420, N(7.0) | Apr 8, 2020 | 9.8 | 30 | NO | NO |
CVE-2025-61610HIGH In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed | Dec 1, 2025 | 7.5 | 27 | NO | NO |
CVE-2025-61616HIGH In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. | Mar 9, 2026 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (635 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unisoc (Shanghai) Technologies Co., Ltd..
Media articles that mention a CVE ID that affects a product developed by Unisoc (Shanghai) Technologies Co., Ltd. — matched by CVE ID, not by vendor name.