← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Malicious SIM Cards Can Execute Code on Cellular IoT Devices and Some Phones

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Malicious SIM cards can execute commands on 9 out of 26 tested devices.
  • Six of eight cellular modules and three of 18 phones were vulnerable.
  • Vulnerable devices primarily use Qualcomm communication processors.
  • Qualcomm and Quectel are implementing fixes, but no public advisories exist.

Vulnerability Discovered in Cellular Devices

Security researchers from the University of Birmingham and Fuzzware found that a malicious SIM card can instruct certain cellular devices to execute attacker-chosen commands. This capability could allow for a complete takeover of devices such as electric-vehicle chargers, industrial routers, and car telematics units.

Affected Hardware and Scope

Out of 26 phones and cellular modules tested, nine were found to be vulnerable. This included six of eight cellular modules and three of 18 phones (OPPO Find X5, OPPO Reno 14 F 5G, and ASUS Zenfone 9). The exposure is primarily in machine-to-machine hardware, with five of the six vulnerable modules being Quectel parts, often found in unattended IoT gear with accessible SIM trays. All nine vulnerable devices utilize Qualcomm communication processors.

Attack Vector and Mitigation Efforts

An attack requires physical access to insert a hostile SIM card. Qualcomm has developed a hardened configuration that disables the vulnerable interface by default for future devices. Quectel has mitigated a file-access flaw and is working on the interface itself. Neither company has published a public advisory, and the module maker's vulnerability portal requires a login to view information. Researchers recommend hardening, deprecating, or disabling the interface entirely.

Recommendations for IoT Fleet Operators

For operators of cellular IoT fleets, the immediate step is to inquire with module suppliers whether the 'RUN AT' command is enabled in their firmware and if it can be disabled. While fixes are expected to reach affected modules via updates, it is unclear if the code paths will be removed or merely switched off. No attacks exploiting this interface have been reported to date.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Researchers discovered that malicious SIM cards can force some cellular IoT modules and phones to run arbitrary commands, potentially leading to full device takeover. This vulnerability affects devices like EV chargers and industrial routers, primarily impacting machine-to-machine hardware with accessible SIM trays. Qualcomm and Quectel are addressing the issue, but no public advisories have been released.