CVE-2025-61616
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-61616 is an improper input validation vulnerability in the NR (New Radio/5G) modem component of Unisoc chipsets (T8100/T9100/T8200/T8300) affecting Android 13.0, 14.0, 15.0, and 16.0. The flaw can cause a system crash, leading to remote denial of service with no privileges required. It was published on March 9, 2026, and addressed in the Android March 2026 security bulletin. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Red Hat Advisory, Unisoc Advisory, Android Bulletin).

Technical details

The root cause is classified as CWE-20 (Improper Input Validation) within the NR modem firmware stack on Unisoc chipsets. An attacker can send specially crafted network-layer input to the modem that bypasses validation checks, triggering a crash of the modem subsystem. No authentication, user interaction, or elevated privileges are required, and the attack vector is entirely network-based. No public technical write-ups or proof-of-concept code have been identified at this time (Unisoc Advisory, Android Bulletin).

Impact

Successful exploitation results in a crash of the NR modem subsystem, causing a denial of service on affected Android devices. The impact is limited to availability — there is no confidentiality or integrity impact, and the scope is unchanged (confined to the affected component). Devices running Android 13, 14, 15, or 16 on Unisoc T8100/T9100/T8200/T8300 chipsets could lose cellular connectivity or experience a full device reboot depending on modem crash recovery behavior (Red Hat Advisory, Unisoc Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.20%, indicating a low probability of exploitation in the near term. Qualys has added detection for this CVE (detection ID 610761) (Red Hat Advisory, Android Bulletin).

Mitigation and workarounds

Patches are available from both Unisoc and Google Android. Users should apply the Android March 2026 security patch level 2026-03-01 or later, which addresses this vulnerability for Android 13, 14, 15, and 16. Device manufacturers using Unisoc chipsets should integrate the fix published in Unisoc's security announcement. No configuration-based workarounds have been publicly documented; applying the available patches is the recommended remediation (Unisoc Advisory, Android Bulletin).

Community reactions

Coverage of CVE-2025-61616 has been limited to automated vulnerability tracking platforms and aggregators such as VulDB, CVEFeed, and Wiz Vulnerability Database. Social media mentions were observed on Mastodon and Bluesky via CVE tracking bots, with no notable researcher commentary or vendor statements beyond the official Unisoc and Google advisories (Android Bulletin, Unisoc Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management