
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-61617 is an improper input validation vulnerability in the NR (New Radio/5G) modem component of Unisoc chipsets, which can cause a system crash leading to remote denial of service. It affects Android versions 13, 14, 15, and 16 running on Unisoc T-series chipsets (T8100/T9100/T8200/T8300). The vulnerability was disclosed on December 1, 2025, as part of the Google Android December 2025 Security Bulletin. It carries a CVSS v3.1 base score of 7.5 (High) (Android Bulletin, Unisoc Advisory).
The vulnerability is classified as CWE-20 (Improper Input Validation) and resides in the NR modem firmware component of Unisoc T-series chipsets. An unauthenticated remote attacker can send specially crafted network-layer input to the modem that bypasses validation checks, triggering a system crash. No privileges or user interaction are required for exploitation, and the attack vector is network-based, making it exploitable over the air via 5G/NR radio protocols (Android Bulletin, Unisoc Advisory).
Successful exploitation results in a complete system crash on the affected device, causing a denial of service with high availability impact. There is no confidentiality or integrity impact — the vulnerability cannot be used to access or modify data. Affected devices running Android 13–16 on Unisoc T8100/T9100/T8200/T8300 chipsets could be rendered temporarily inoperable by a remote attacker without any interaction from the device owner (Android Bulletin, Unisoc Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.0015 (0.15%), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Android Bulletin, Unisoc Advisory).
Users should apply the security patch released in the Google Android December 2025 Security Bulletin (patch level 2025-12-01), which addresses this vulnerability for Android 13, 14, 15, and 16 on affected Unisoc T-series devices. Device manufacturers and OEMs should integrate and distribute the patch promptly. As a temporary measure where patching is not immediately feasible, network-level filtering of anomalous 5G/NR signaling traffic may reduce exposure, and isolating affected devices from untrusted networks is advisable (Android Bulletin, Unisoc Advisory).
The vulnerability was noted in coverage of Google's December 2025 Android security bulletin, which addressed over 100 vulnerabilities. General media coverage highlighted the breadth of the patch batch rather than this specific CVE (BeyondMachines). No significant independent researcher commentary or social media discussion specific to CVE-2025-61617 has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."