logo

Critical UNISOC T612 Modem Flaw Enables Remote Code Execution via Cellular Calls

ID: d92fe6fb-3469-5c96-89d0-84440395bc65

STIX ID: report--d92fe6fb-3469-5c96-89d0-84440395bc65

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-20

Date Updated: 2026-07-21

Author: Divya

...
...

A critical remote code execution vulnerability in UNISOC modem firmware (CWE-674) allows an attacker to trigger uncontrolled recursion via crafted SDP 'acap' attributes during SIP/IMS calls, overflowing the modem stack and enabling full RCE on affected chipsets (T612, T616, T606, T7250); researchers reproduced a working exploit on a Realme C33 and no patch is available, leaving many devices vulnerable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.