AI Weekly Malaysia

Back to items Summaries

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

ID
13100
Status
summarized
Published
11 Aug 2026, 8:05 PM
Fetched
11 Aug 2026, 10:26 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
5.5
Created
11 Aug 2026, 10:27 PM
Tags
Audience
developers

What happened

Researchers from the University of Birmingham and Fuzzware found that a malicious SIM card can execute attacker-chosen code on cellular modems via a 'RUN AT' interface, present in 9 of 26 devices tested. Six of eight cellular modules accepted the command—including five Quectel parts pulled from an EV charger, industrial router, and car telematics unit—while only 3 of 18 phones did (OPPO Find X5, OPPO Reno 14 F 5G, ASUS Zenfone 9). All nine vulnerable devices run Qualcomm communication processors; Qualcomm has built a hardened config that disables the interface by default for future devices, but neither Qualcomm nor Quectel has published a public advisory.

Why it matters

If you ship or operate cellular IoT fleets—EV chargers, industrial routers, telematics—ask your module supplier today whether RUN AT is enabled in the firmware they ship, since there is no central patch and Quectel's vulnerability portal is login-walled. The attack requires physical SIM access, so unattended devices with accessible SIM trays and few other interfaces are the highest-risk targets.

Discussion angle

For anyone in the room building or sourcing cellular IoT hardware: do you know what firmware config your Quectel modules ship with, and is RUN AT on or off? This is a supply-chain question, not a patch-you-can-apply question.

Top