Vulnerabilidades em Unisoc (Shanghai) Technologies Co., Ltd.

656 resultados
Análise Vexday

Com 647 CVEs catalogadas e nenhuma presença no catálogo KEV da CISA, a Unisoc apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere baixa pressão ofensiva documentada no momento. O tipo de falha mais recorrente é CWE-862 (ausência de verificação de autorização), padrão que, quando explorado, permite acesso não autorizado a recursos ou funcionalidades restritas e merece atenção especial em revisões de código e hardening. A CVE mais relevante no contexto atual é CVE-2025-31715, com escore EPSS de 0,0156, indicando probabilidade de exploração ainda baixa, mas que deve ser monitorada dado seu destaque entre as ameaças ativas. As 6 vulnerabilidades surgidas nos últimos 90 dias e a ausência de PoCs públicas apontam para um perfil de risco moderado, embora a presença de 4 CVEs críticas reforce a necessidade de acompanhamento contínuo das atualizações do fabricante.

CVE-2026-4967HIGHIn IMS, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additionalEPSS 0.4%CVE-2026-21548HIGHIn nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges neeEPSS 0.4%CVE-2023-40632In jpg driver, there is a possible use after free due to a logic error. This could lead to remote information disclosure no additional execuEPSS 0.4%CVE-2023-33914In NIA0 algorithm in Security Mode Command, there is a possible missing verification incorrect input. This could lead to remote information EPSS 0.4%CVE-2023-52533MEDIUMIn modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosuEPSS 0.4%CVE-2023-52344MEDIUMIn modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosuEPSS 0.4%CVE-2023-33915In LTE protocol stack, there is a possible missing permission check. This could lead to remote information disclosure no additional executioEPSS 0.3%CVE-2023-52341HIGHIn Plaintext COUNTER CHECK message accepted before AS security activation, there is a possible missing permission check. This could lead to EPSS 0.3%CVE-2022-38691HIGHIn BootROM, there is a possible missing validation for Certificate Type 0. This could lead to local escalation of privilege with no additionEPSS 0.3%CVE-2023-52342HIGHIn modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosuEPSS 0.3%CVE-2025-71252HIGHIn Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilEPSS 0.3%CVE-2023-52534MEDIUMIn ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote denial of service with no additioEPSS 0.3%CVE-2025-71254HIGHIn Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilEPSS 0.3%CVE-2025-71253HIGHIn Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilEPSS 0.3%CVE-2025-61614HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.3%CVE-2025-61615HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.3%CVE-2025-61613HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.3%CVE-2025-71255HIGHIn Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilEPSS 0.3%CVE-2025-61616HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.3%CVE-2025-61612HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.3%