A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
Researchers from the University of Birmingham and Fuzzware have released a proof-of-concept demonstrating that malicious SIM cards can execute arbitrary code within cellular IoT devices, including electric vehicle chargers and industrial routers. By exploiting the standard RUN AT command feature on modems from vendors such as Qualcomm and Quectel, attackers can gain full control over the device's underlying operating system. The study identified the interface vulnerability as CVE-2026-57550 (tracked as CVD-2026-0122 by the GSMA) and confirmed impact across multiple products, including specific models from Autel, OPPO, and ASUS. While no active exploitation has been reported, vendors are advised to ensure the interface is disabled or patched to prevent potential compromise.