Vulnerabilidades em Unisoc (Shanghai) Technologies Co., Ltd.

656 resultados
Análise Vexday

Com 647 CVEs catalogadas e nenhuma presença no catálogo KEV da CISA, a Unisoc apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere baixa pressão ofensiva documentada no momento. O tipo de falha mais recorrente é CWE-862 (ausência de verificação de autorização), padrão que, quando explorado, permite acesso não autorizado a recursos ou funcionalidades restritas e merece atenção especial em revisões de código e hardening. A CVE mais relevante no contexto atual é CVE-2025-31715, com escore EPSS de 0,0156, indicando probabilidade de exploração ainda baixa, mas que deve ser monitorada dado seu destaque entre as ameaças ativas. As 6 vulnerabilidades surgidas nos últimos 90 dias e a ausência de PoCs públicas apontam para um perfil de risco moderado, embora a presença de 4 CVEs críticas reforce a necessidade de acompanhamento contínuo das atualizações do fabricante.

CVE-2025-31715CRITICALIn vowifi service, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilegeEPSS 1.5%CVE-2022-38696CRITICALIn BootRom, there's a possible missing payload size check. This could lead to memory buffer overflow without requiring additional execution EPSS 0.8%CVE-2022-38693CRITICALIn FDL1, there is a possible missing payload size check. This could lead to memory buffer overflow without requiring additional execution prEPSS 0.8%CVE-2025-31713HIGHIn engineer mode service, there is a possible command injection due to improper input validation. This could lead to local escalation of priEPSS 0.7%CVE-2025-31717HIGHIn modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional EPSS 0.6%CVE-2025-31718HIGHIn modem, there is a possible system crash due to improper input validation. This could lead to remote escalation of privilege with no additEPSS 0.6%CVE-2022-38694HIGHIn BootRom, there is a possible unchecked write address. This could lead to local escalation of privilege with no additional execution priviEPSS 0.6%CVE-2025-61611HIGHIn modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilegeEPSS 0.6%CVE-2023-33913In DRM/oemcrypto, there is a possible out of bounds write due to an incorrect calculation of buffer size.This could lead to remote escalatioEPSS 0.5%CVE-2022-38692CRITICALIn BootROM, there is a missing size check for RSA keys in Certificate Type 0 validation. This could lead to memory buffer overflow without rEPSS 0.5%CVE-2023-42717In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional executionEPSS 0.4%CVE-2023-42716HIGHIn telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional executionEPSS 0.4%CVE-2026-21550HIGHIn modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilegesEPSS 0.4%CVE-2025-31710MEDIUMIn engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privEPSS 0.4%CVE-2026-21553HIGHIn modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilegesEPSS 0.4%CVE-2026-21554HIGHIn modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilegesEPSS 0.4%CVE-2026-21549HIGHIn modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilegesEPSS 0.4%CVE-2026-21555HIGHIn modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilegesEPSS 0.4%CVE-2026-21552HIGHIn modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilegesEPSS 0.4%CVE-2026-21551HIGHIn modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilegesEPSS 0.4%