CVE-2025-61607
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-61607 is an improper input validation vulnerability in the NR (New Radio/5G) modem component affecting Android devices running on Unisoc chipsets. It can cause a system crash, leading to remote denial of service with no privileges required. The vulnerability was disclosed on December 1, 2025, as part of the Google Android Security Bulletin and affects Android versions 13, 14, 15, and 16 on Unisoc T8100/T9100/T8200/T8300 platforms. It carries a CVSS v3.1 base score of 7.5 (High) (Android Bulletin, Unisoc Advisory).

Technical details

The vulnerability is classified under CWE-20 (Improper Input Validation) and resides in the NR modem subsystem of Unisoc chipsets. An attacker can send specially crafted network-level input that the modem fails to properly validate, triggering a system crash. The attack vector is network-based, requires no authentication or user interaction, and has low attack complexity, making it straightforward to exploit remotely. No public proof-of-concept code has been identified at this time (Android Bulletin, Unisoc Advisory).

Impact

Successful exploitation results in a system crash on the affected Android device, causing a denial of service condition that renders the device temporarily unavailable to its user. There is no impact on confidentiality or data integrity — the sole consequence is loss of availability. The attack can be launched remotely over the network without any privileges or user interaction, affecting all Android 13–16 devices running on Unisoc T8100, T9100, T8200, or T8300 chipsets (Android Bulletin, Unisoc Advisory).

Mitigation and workarounds

Google released a patch for this vulnerability in the Android Security Bulletin dated December 1, 2025. Users should apply the December 2025 security patch level or later to affected devices. Unisoc has also published a dedicated advisory for T8100/T9100/T8200/T8300 platform users. As a network-level workaround, administrators can implement network traffic filtering to restrict unexpected or malformed 5G NR signaling to affected devices until patches are applied (Android Bulletin, Unisoc Advisory).

Community reactions

The vulnerability was noted in broader coverage of Google's December 2025 Android Security Bulletin, which addressed over 100 vulnerabilities. Coverage appeared on security news aggregators and community platforms including CyberHub Blog and TheCyberThrone, with no significant controversy or notable researcher commentary specific to this CVE (Android Bulletin).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68981HIGH8.8
  • NixOS logoNixOS
  • cpe:2.3:a:apache:nifi
NoYesAug 03, 2026
CVE-2026-69153MEDIUM6.3
  • JavaScript logoJavaScript
  • pcs
NoYesAug 03, 2026
CVE-2026-68979MEDIUM5.9
  • NixOS logoNixOS
  • cpe:2.3:a:apache:nifi
NoYesAug 03, 2026
CVE-2026-68980LOW2.3
  • NixOS logoNixOS
  • cpe:2.3:a:apache:nifi
NoYesAug 03, 2026
CVE-2026-54522LOW2.1
  • Ruby logoRuby
  • ruby4.0-msgpack
NoYesJul 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management