Vulnerabilidades en Unisoc (Shanghai) Technologies Co., Ltd.

656 resultados
Análisis Vexday

Com 647 CVEs catalogadas e nenhuma presença no catálogo KEV da CISA, a Unisoc apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere baixa pressão ofensiva documentada no momento. O tipo de falha mais recorrente é CWE-862 (ausência de verificação de autorização), padrão que, quando explorado, permite acesso não autorizado a recursos ou funcionalidades restritas e merece atenção especial em revisões de código e hardening. A CVE mais relevante no contexto atual é CVE-2025-31715, com escore EPSS de 0,0156, indicando probabilidade de exploração ainda baixa, mas que deve ser monitorada dado seu destaque entre as ameaças ativas. As 6 vulnerabilidades surgidas nos últimos 90 dias e a ausência de PoCs públicas apontam para um perfil de risco moderado, embora a presença de 4 CVEs críticas reforce a necessidade de acompanhamento contínuo das atualizações do fabricante.

CVE-2025-71251HIGHIn IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional exEPSS 0.3%CVE-2025-71256HIGHIn nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileEPSS 0.3%CVE-2023-52343MEDIUMIn SecurityCommand message after as security has been actived., there is a possible improper input validation. This could lead to remote infEPSS 0.3%CVE-2025-31714MEDIUMIn Developer Tools, there is a possible missing verification incorrect input. This could lead to local escalation of privilege with no additEPSS 0.3%CVE-2022-47339MEDIUMIn cmd services, there is a OS command injection issue due to missing permission check. This could lead to local escalation of privilege witEPSS 0.3%CVE-2022-42768MEDIUMIn wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.EPSS 0.3%CVE-2024-39437MEDIUMIn linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of pEPSS 0.3%CVE-2024-39438MEDIUMIn linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of pEPSS 0.3%CVE-2025-3012HIGHIn dpc modem, there is a possible system crash due to null pointer dereference. This could lead to remote denial of service with no additionEPSS 0.3%CVE-2024-39436MEDIUMIn linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of pEPSS 0.3%CVE-2025-61617HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.2%CVE-2025-61610HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.2%CVE-2025-11133HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.2%CVE-2025-61609HIGHIn modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional EPSS 0.2%CVE-2025-11132HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.2%CVE-2025-11131HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.2%CVE-2025-61607HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.2%CVE-2025-61608HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.2%CVE-2025-61619HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.2%CVE-2025-61618HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.2%