
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-61616 is an improper input validation vulnerability in the NR (New Radio/5G) modem component of Unisoc chipsets (T8100/T9100/T8200/T8300) affecting Android 13.0, 14.0, 15.0, and 16.0. The flaw can cause a system crash, leading to remote denial of service with no privileges required. It was published on March 9, 2026, and addressed in the Android March 2026 security bulletin. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Red Hat Advisory, Unisoc Advisory, Android Bulletin).
The root cause is classified as CWE-20 (Improper Input Validation) within the NR modem firmware stack on Unisoc chipsets. An attacker can send specially crafted network-layer input to the modem that bypasses validation checks, triggering a crash of the modem subsystem. No authentication, user interaction, or elevated privileges are required, and the attack vector is entirely network-based. No public technical write-ups or proof-of-concept code have been identified at this time (Unisoc Advisory, Android Bulletin).
Successful exploitation results in a crash of the NR modem subsystem, causing a denial of service on affected Android devices. The impact is limited to availability — there is no confidentiality or integrity impact, and the scope is unchanged (confined to the affected component). Devices running Android 13, 14, 15, or 16 on Unisoc T8100/T9100/T8200/T8300 chipsets could lose cellular connectivity or experience a full device reboot depending on modem crash recovery behavior (Red Hat Advisory, Unisoc Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.20%, indicating a low probability of exploitation in the near term. Qualys has added detection for this CVE (detection ID 610761) (Red Hat Advisory, Android Bulletin).
Patches are available from both Unisoc and Google Android. Users should apply the Android March 2026 security patch level 2026-03-01 or later, which addresses this vulnerability for Android 13, 14, 15, and 16. Device manufacturers using Unisoc chipsets should integrate the fix published in Unisoc's security announcement. No configuration-based workarounds have been publicly documented; applying the available patches is the recommended remediation (Unisoc Advisory, Android Bulletin).
Coverage of CVE-2025-61616 has been limited to automated vulnerability tracking platforms and aggregators such as VulDB, CVEFeed, and Wiz Vulnerability Database. Social media mentions were observed on Mastodon and Bluesky via CVE tracking bots, with no notable researcher commentary or vendor statements beyond the official Unisoc and Google advisories (Android Bulletin, Unisoc Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."