CVE Tools

Вредоносная SIM-карта может выполнить код на устройстве и похитить данные

Хакер (xakep.ru)By Мария Нефёдова

ResearchSIM cardsAutel Charging Stations

Our summary

Researchers from the University of Birmingham and Fuzzware demonstrated that a compromised SIM card can send AT commands to force arbitrary code execution, file exfiltration, and network degradation on connected devices. The study tested 26 devices using a new toolkit called CATana, finding vulnerabilities in several smartphones including the Oppo Find X5, Oppo Reno 14 F 5G, and Asus Zenfone 9, as well as multiple IoT modulators. Notably, the team achieved code execution on an Autel charging station equipped with a Quectel EC25-AFX module.

The issue stems from standard proactive SIM command specifications allowing RUN AT instructions, which vendors should disable or retire. Related fixes were issued for CVE-2025-48618 (Google) earlier, while current tracking identifiers include CVE-2026-57550 (Qualcomm) and CVD-2026-0122 (GSMA).

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store