CVE-2025-31713 Details
Description
In engineer mode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.
A command injection vulnerability has been identified in the engineer mode service of certain UNISOC Android chipsets. This issue arises from improper input validation, which could lead to local privilege escalation without requiring additional execution privileges. The vulnerability affects chipsets including SL8521E, SL8521ET, SL8541E, UIS8141E, UWS6137, UWS6137E, UWS6151E, and UWS6152, on software versions Mocor5, Android 8.1, and Android 9.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 18, 2025CISA-ADP
Assessed Aug 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.unisoc.com/en_us/secy/announcementDetail/1944933773300793346 | [email protected] | AdvisoryBundleVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| UNISOC SL8521E | All versions |
CPE
Remediation
| |
| UNISOC SL8521ET | All versions |
CPE
Remediation
| |
| UNISOC SL8541E | All versions |
CPE
Remediation
| |
| UNISOC UIS8141E | All versions |
CPE
Remediation
| |
| UNISOC UWS6137 | All versions |
CPE
Remediation
| |
| UNISOC UWS6137E | All versions |
CPE
Remediation
| |
| UNISOC UWS6151E | All versions |
CPE
Remediation
| |
| UNISOC UWS6152 | All versions |
CPE
Remediation
| |
| UNISOC Mocor5 | All versions |
CPE
Remediation
| |
| Android | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 18, 2025 | New CVE Received | [email protected] |
Volerion