A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
- ID
- 13100
- Status
- summarized
- Published
- 11 Aug 2026, 8:05 PM
- Fetched
- 11 Aug 2026, 10:26 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 11 Aug 2026, 10:27 PM
- Tags
- Audience
- developers
What happened
Researchers from the University of Birmingham and Fuzzware found that a malicious SIM card can execute attacker-chosen code on cellular modems via a 'RUN AT' interface, present in 9 of 26 devices tested. Six of eight cellular modules accepted the command—including five Quectel parts pulled from an EV charger, industrial router, and car telematics unit—while only 3 of 18 phones did (OPPO Find X5, OPPO Reno 14 F 5G, ASUS Zenfone 9). All nine vulnerable devices run Qualcomm communication processors; Qualcomm has built a hardened config that disables the interface by default for future devices, but neither Qualcomm nor Quectel has published a public advisory.
Why it matters
If you ship or operate cellular IoT fleets—EV chargers, industrial routers, telematics—ask your module supplier today whether RUN AT is enabled in the firmware they ship, since there is no central patch and Quectel's vulnerability portal is login-walled. The attack requires physical SIM access, so unattended devices with accessible SIM trays and few other interfaces are the highest-risk targets.
Discussion angle
For anyone in the room building or sourcing cellular IoT hardware: do you know what firmware config your Quectel modules ship with, and is RUN AT on or off? This is a supply-chain question, not a patch-you-can-apply question.