Vulnerabilities in Unisoc (Shanghai) Technologies Co., Ltd.

656 results
Vexday analysis

Com 647 CVEs catalogadas e nenhuma presença no catálogo KEV da CISA, a Unisoc apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere baixa pressão ofensiva documentada no momento. O tipo de falha mais recorrente é CWE-862 (ausência de verificação de autorização), padrão que, quando explorado, permite acesso não autorizado a recursos ou funcionalidades restritas e merece atenção especial em revisões de código e hardening. A CVE mais relevante no contexto atual é CVE-2025-31715, com escore EPSS de 0,0156, indicando probabilidade de exploração ainda baixa, mas que deve ser monitorada dado seu destaque entre as ameaças ativas. As 6 vulnerabilidades surgidas nos últimos 90 dias e a ausência de PoCs públicas apontam para um perfil de risco moderado, embora a presença de 4 CVEs críticas reforce a necessidade de acompanhamento contínuo das atualizações do fabricante.

CVE-2022-2985HIGHIn music service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execEPSS 0.2%CVE-2022-38670HIGHIn soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additioEPSS 0.2%CVE-2022-39110HIGHIn Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional executiEPSS 0.2%CVE-2022-39080HIGHIn messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional EPSS 0.2%CVE-2022-39111HIGHIn Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional executiEPSS 0.2%CVE-2022-39107HIGHIn Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorder service with no adEPSS 0.2%CVE-2022-39109HIGHIn Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional executiEPSS 0.2%CVE-2022-38698HIGHIn messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional EPSS 0.2%CVE-2022-39108HIGHIn Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional executiEPSS 0.2%CVE-2022-39092HIGHIn power management service, there is a missing permission check. This could lead to set up power management service with no additional execEPSS 0.2%CVE-2022-39091HIGHIn power management service, there is a missing permission check. This could lead to set up power management service with no additional execEPSS 0.2%CVE-2022-39090HIGHIn power management service, there is a missing permission check. This could lead to set up power management service with no additional execEPSS 0.2%CVE-2022-39100HIGHIn power management service, there is a missing permission check. This could lead to set up power management service with no additional execEPSS 0.1%CVE-2022-39096HIGHIn power management service, there is a missing permission check. This could lead to set up power management service with no additional execEPSS 0.1%CVE-2022-39094HIGHIn power management service, there is a missing permission check. This could lead to set up power management service with no additional execEPSS 0.1%CVE-2022-39101HIGHIn power management service, there is a missing permission check. This could lead to set up power management service with no additional execEPSS 0.1%CVE-2022-39102HIGHIn power management service, there is a missing permission check. This could lead to set up power management service with no additional execEPSS 0.1%CVE-2022-39099HIGHIn power management service, there is a missing permission check. This could lead to set up power management service with no additional execEPSS 0.1%CVE-2022-39095HIGHIn power management service, there is a missing permission check. This could lead to set up power management service with no additional execEPSS 0.1%CVE-2022-38688MEDIUMIn telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privEPSS 0.1%