< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-11T17:35:03+05:30

Exploiting SIM Card Vulnerabilities to Execute Malicious Code on Cellular IoT Modems

A vulnerability in cellular IoT devices allows malicious SIM cards to execute arbitrary code via the SIM's AT command interface, affecting 9 out of 26 tested devices, including EV chargers and industrial routers. The flaw stems from an exposed interface in Qualcomm-based modems, with vendors like Quectel and Qualcomm acknowledging the issue but no public patches yet.

A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over.

Researchers at the University of Birmingham and the security firm Fuzzware tested 26 phones and cellular modules for the capability, found it

Read original article

*** END OF TRANSMISSION ***