CVE Tools
Back to feed
PoC public EV Chargers ics-ot-iot Cellular Modules Qualcomm rce

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

The Hacker News·By The Hacker News··6 min read
CVE Tools coverage

Researchers from the University of Birmingham and Fuzzware have released a proof-of-concept demonstrating that malicious SIM cards can execute arbitrary code within cellular IoT devices, including electric vehicle chargers and industrial routers. By exploiting the standard RUN AT command feature on modems from vendors such as Qualcomm and Quectel, attackers can gain full control over the device's underlying operating system. The study identified the interface vulnerability as CVE-2026-57550 (tracked as CVD-2026-0122 by the GSMA) and confirmed impact across multiple products, including specific models from Autel, OPPO, and ASUS. While no active exploitation has been reported, vendors are advised to ensure the interface is disabled or patched to prevent potential compromise.