CVE Tools

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

The Hacker NewsBy The Hacker News

PoC publicEV ChargersCellular Modules

Our summary

Researchers from the University of Birmingham and Fuzzware have released a proof-of-concept demonstrating that malicious SIM cards can execute arbitrary code within cellular IoT devices, including electric vehicle chargers and industrial routers. By exploiting the standard RUN AT command feature on modems from vendors such as Qualcomm and Quectel, attackers can gain full control over the device's underlying operating system. The study identified the interface vulnerability as CVE-2026-57550 (tracked as CVD-2026-0122 by the GSMA) and confirmed impact across multiple products, including specific models from Autel, OPPO, and ASUS. While no active exploitation has been reported, vendors are advised to ensure the interface is disabled or patched to prevent potential compromise.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store