Vulnerabilidades en Unisoc (Shanghai) Technologies Co., Ltd.

656 resultados
Análisis Vexday

Com 647 CVEs catalogadas e nenhuma presença no catálogo KEV da CISA, a Unisoc apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere baixa pressão ofensiva documentada no momento. O tipo de falha mais recorrente é CWE-862 (ausência de verificação de autorização), padrão que, quando explorado, permite acesso não autorizado a recursos ou funcionalidades restritas e merece atenção especial em revisões de código e hardening. A CVE mais relevante no contexto atual é CVE-2025-31715, com escore EPSS de 0,0156, indicando probabilidade de exploração ainda baixa, mas que deve ser monitorada dado seu destaque entre as ameaças ativas. As 6 vulnerabilidades surgidas nos últimos 90 dias e a ausência de PoCs públicas apontam para um perfil de risco moderado, embora a presença de 4 CVEs críticas reforce a necessidade de acompanhamento contínuo das atualizações do fabricante.

CVE-2025-69278HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.2%CVE-2025-69279HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.2%CVE-2023-33898In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privEPSS 0.2%CVE-2022-39087MEDIUMIn network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges nEPSS 0.2%CVE-2022-39088MEDIUMIn network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges nEPSS 0.2%CVE-2022-39084MEDIUMIn network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges nEPSS 0.2%CVE-2022-39082MEDIUMIn network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges nEPSS 0.2%CVE-2022-39086MEDIUMIn network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges nEPSS 0.2%CVE-2022-39085MEDIUMIn network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges nEPSS 0.2%CVE-2022-39081MEDIUMIn network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges nEPSS 0.2%CVE-2022-39083MEDIUMIn network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges nEPSS 0.2%CVE-2022-38695HIGHIn BootRom, there's a possible unchecked command index. This could lead to local escalation of privilege with no additional execution privilEPSS 0.2%CVE-2022-39117HIGHIn messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privEPSS 0.2%CVE-2024-39442MEDIUMIn sprd ssense service, there is a possible missing permission check. This could lead to local information disclosure with no additional exeEPSS 0.2%CVE-2024-39432HIGHIn UMTS RLC driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with SEPSS 0.2%CVE-2024-39431HIGHIn UMTS RLC driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with EPSS 0.2%CVE-2022-38689MEDIUMIn telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privEPSS 0.2%CVE-2023-33902In bluetooth service, there is a missing permission check. This could lead to local information disclosure with no additional execution privEPSS 0.2%CVE-2022-47451MEDIUMIn wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.EPSS 0.2%CVE-2022-38669HIGHIn soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additioEPSS 0.2%