Command injection in UNISOC products - CVE-2025-31710
Published: July 7, 2025 / Updated: July 18, 2025
Vulnerability identifier: #VU112347
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-31710
CWE-ID: CWE-77
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a local application to read and manipulate data.
The vulnerability exists due to a possible command injection due to improper input validation within the engineermode service in Android. A local application can read and manipulate data.
Affected software
SC9863A
T606
T612
T616
T750
T765
T760
T770
T820
S8000
T8300
T9300
T606
T612
T616
T750
T765
T760
T770
T820
S8000
T8300
T9300
How to mitigate CVE-2025-31710
Install security update from vendor's website.