Security researchers from the University of Birmingham and Fuzzware found that a malicious SIM card can instruct certain cellular devices to execute attacker-chosen commands. This capability could allow for a complete takeover of devices such as electric-vehicle chargers, industrial routers, and car telematics units.
Out of 26 phones and cellular modules tested, nine were found to be vulnerable. This included six of eight cellular modules and three of 18 phones (OPPO Find X5, OPPO Reno 14 F 5G, and ASUS Zenfone 9). The exposure is primarily in machine-to-machine hardware, with five of the six vulnerable modules being Quectel parts, often found in unattended IoT gear with accessible SIM trays. All nine vulnerable devices utilize Qualcomm communication processors.
An attack requires physical access to insert a hostile SIM card. Qualcomm has developed a hardened configuration that disables the vulnerable interface by default for future devices. Quectel has mitigated a file-access flaw and is working on the interface itself. Neither company has published a public advisory, and the module maker's vulnerability portal requires a login to view information. Researchers recommend hardening, deprecating, or disabling the interface entirely.
For operators of cellular IoT fleets, the immediate step is to inquire with module suppliers whether the 'RUN AT' command is enabled in their firmware and if it can be disabled. While fixes are expected to reach affected modules via updates, it is unclear if the code paths will be removed or merely switched off. No attacks exploiting this interface have been reported to date.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Researchers discovered that malicious SIM cards can force some cellular IoT modules and phones to run arbitrary commands, potentially leading to full device takeover. This vulnerability affects devices like EV chargers and industrial routers, primarily impacting machine-to-machine hardware with accessible SIM trays. Qualcomm and Quectel are addressing the issue, but no public advisories have been released.