Improper initialization in UNISOC products - CVE-2025-31719
Published: December 1, 2025
Vulnerability identifier: #VU118909
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-31719
CWE-ID: CWE-665
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to bypass implemented security restrictions.
The vulnerability exists due to improper initialization in TEE EcDSA algorithm, which results in generation of incorrect signature results with low probability. A local application can bypass implemented security restrictions.
Affected software
T618
T9300
T8300
S8000
T820
T770
T760
T765
T750
SC7731E
T610
T616
T612
T606
T310
SC9863A
SC9832E
T9300
T8300
S8000
T820
T770
T760
T765
T750
SC7731E
T610
T616
T612
T606
T310
SC9863A
SC9832E
How to mitigate CVE-2025-31719
Install updates from vendor's website.