Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Unisoc (Shanghai) Technologies Co., Ltd.

First CVE: Apr 8, 2020Active for: 6 yearsTotal CVEs: 635
17.4
VTI Score
Low

Unisoc is a mobile system-on-chip (SoC) vendor whose products power a broad range of smartphones and embedded devices, particularly in mid-range and emerging-market segments; its disclosure footprint reflects the complexity of firmware and baseband components that integrate multiple memory-intensive subsystems. The vendor's vulnerability portfolio concentrates in its core SoC product lines, including the SC9863A, T610, T618, T606, and T612, and recurs through weakness classes centered on memory-safety boundaries—out-of-bounds writes and reads, buffer overflows, and missing authorization controls in firmware layers. These patterns are structural to the firmware and drivers embedded in low-level device operation, where validation gaps can affect multiple vendors' derivative products and affect the security of millions of downstream deployments. Defenders should track Unisoc SoC disclosures closely when evaluating device firmware and coordinate updates through OEM release cycles, since remediation typically requires vendor integration and device-specific builds. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
635
Total CVEs
More Total CVEs than 100% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Unisoc (Shanghai) Technologies Co., Ltd. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 8, 2020
6 years ago
Most Recent CVE
May 6, 2026
80 days ago

Self-Reporting Analysis

Of all the CVEs published by Unisoc (Shanghai) Technologies Co., Ltd. as a CNA, 97.7% affect products that Unisoc (Shanghai) Technologies Co., Ltd. develops as a vendor.

97.7%
Self-reported: 633 (97.7%)
Third-party: 15 (2.3%)

Of all the CVEs published that affect products developed by Unisoc (Shanghai) Technologies Co., Ltd., 99.7% are self-published by Unisoc (Shanghai) Technologies Co., Ltd. as a CNA.

99.7%
Self-published: 633 (99.7%)
Other CNAs: 2 (0.3%)

Products(54 total)

Top CVEs

Signals from CVEs in this vendor scope (635 CVEs).

635 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-71254HIGH
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
May 6, 20267.533NONO
CVE-2025-71252HIGH
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
May 6, 20267.533NONO
CVE-2025-71255HIGH
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
May 6, 20267.532NONO
CVE-2022-27250CRITICAL
The UNISOC chipset through 2022-03-15 allows attackers to obtain remote control of a mobile phone, e.g., to obtain sensitive information from text messages or the device's screen,
Mar 18, 20229.832NONO
CVE-2025-71256HIGH
In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
May 6, 20267.530NONO
CVE-2025-71253HIGH
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
May 6, 20267.530NONO
CVE-2025-71251HIGH
In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
May 6, 20267.530NONO
CVE-2018-21054CRITICAL
An issue was discovered on Samsung mobile devices with M(6.0), N(7.x) and O(8.x) except exynos9610/9820 in all Platforms, M(6.0) except MSM8909 SC77xx/9830 exynos3470/5420, N(7.0)
Apr 8, 20209.830NONO
CVE-2025-61610HIGH
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Dec 1, 20257.527NONO
CVE-2025-61616HIGH
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
Mar 9, 20267.526NONO
View all 635 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products635 CVEs
79%
20%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local593 (93.4%)
Network40 (6.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (0.3%)
Attack Complexity
Low628 (98.9%)
High7 (1.1%)
Unknown0 (0.0%)
User Interaction
None633 (99.7%)
Unknown0 (0.0%)
Required2 (0.3%)
Privileges Required
Low476 (75.0%)
High114 (18.0%)
None45 (7.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (635 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Unisoc (Shanghai) Technologies Co., Ltd..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Unisoc (Shanghai) Technologies Co., Ltd. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Unisoc (Shanghai) Technologies Co., Ltd.'s Products

View all 2 CNAs →

Top CWEs