Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices: A New Frontier in IoT Security Threats



A recent discovery has revealed a malicious SIM card vulnerability in cellular IoT devices, allowing an attacker to execute commands on the device's modem. The exposure affects various IoT devices, including electric-vehicle chargers, industrial routers, and car telematics units, and highlights a new frontier in IoT security threats.

  • A malicious SIM card vulnerability has been discovered in cellular IoT devices, allowing an attacker to execute commands on the device's modem.
  • The vulnerability was found in 9 out of 26 phones and cellular modules tested, with 5 affected Quectel parts already compromised in industrial applications.
  • The exposure affects various IoT devices beyond mobile devices, including electric-vehicle chargers, industrial routers, and car telematics units.
  • Only 3 phones (OPPO Find X5, OPPO Reno 14 F 5G, and ASUS Zenfone 9) accepted the command, while 6 out of 8 cellular modules were vulnerable.
  • A hostile SIM card can power devices down, shut off modems, or read arbitrary files off a device's filesystem.
  • Vendors have taken different approaches to addressing the vulnerability, with some implementing hardened configurations and others claiming mitigation efforts.
  • There is no single patch for this vulnerability, and many IoT devices are not receiving firmware updates in a timely manner.



  • The recent discovery of a malicious SIM card vulnerability in cellular IoT devices has sent shockwaves throughout the cybersecurity community, highlighting a new and alarming threat to the security of these interconnected devices. According to researchers at the University of Birmingham and the security firm Fuzzware, a malicious SIM card can take control of the modem inside the device it sits in, allowing an attacker to execute commands of their choosing.

    This vulnerability was found in nine out of 26 phones and cellular modules tested by the researchers, who discovered that five of the six affected Quectel parts had already been compromised in industrial applications. The exposure is not limited to mobile devices alone but also affects various IoT devices such as electric-vehicle chargers, industrial routers, and car telematics units.

    The SIM card's proactive capability, which allows it to send commands to the modem, opens up a wide attack surface that can be exploited by attackers. The researchers found that six out of eight cellular modules they tested accepted the command, while only three phones did: the OPPO Find X5, the OPPO Reno 14 F 5G, and the ASUS Zenfone 9.

    In one notable case study, an attacker was able to take control of a commercial EV charger using a malicious SIM card. The team's tooling, released as CATana, found that a hostile SIM could power the handset down, shut off the modem, or even read arbitrary files off the device's filesystem.

    The researchers' position is that the interface should be hardened, deprecated, or disabled outright to prevent such attacks in the future. However, vendors have taken different approaches to addressing this vulnerability. Qualcomm has built a hardened configuration that switches the interface off by default, while Quectel claims to have mitigated the file-access flaw and is still working on the interface itself.

    Despite these efforts, there is no single patch for this vulnerability, and many IoT devices are not receiving firmware updates in a timely manner. The lack of transparency from vendors, who have not published affected or fixed version numbers, has made it difficult to assess the scope of the problem.

    The researchers' findings have been reported to Google, Oppo, Quectel, Semtech, and Qualcomm in March 2026, but many vendors have treated these reports as informative rather than a call to action. The exposure is tracked as CVE-2026-57550, assigned through Qualcomm, but the CVE record has yet to appear in the CVE Program's published list.

    In conclusion, the recent discovery of this malicious SIM card vulnerability highlights the growing threat landscape for IoT devices. As these devices become increasingly connected and interdependent, they also create new vulnerabilities that can be exploited by attackers. It is essential for vendors, regulators, and consumers to take proactive steps to address this vulnerability and ensure the security of our increasingly IoT-driven world.


    A recent discovery has revealed a malicious SIM card vulnerability in cellular IoT devices, allowing an attacker to execute commands on the device's modem. The exposure affects various IoT devices, including electric-vehicle chargers, industrial routers, and car telematics units, and highlights a new frontier in IoT security threats.




    Related Information:
  • https://www.ethicalhackingnews.com/articles/A-Malicious-SIM-Card-Can-Run-Attacker-Code-Inside-the-Modems-Behind-Cellular-IoT-Devices-A-New-Frontier-in-IoT-Security-Threats-ehn.shtml

  • https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html


  • Published: Tue Aug 11 08:36:42 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us