CVE Tools
Back to feed
Research SIM cards ics-ot-iot Autel Charging Stations Qualcomm mobile

Вредоносная SIM-карта может выполнить код на устройстве и похитить данные

Хакер (xakep.ru)·By Мария Нефёдова··3 min read
CVE Tools coverage

Researchers from the University of Birmingham and Fuzzware demonstrated that a compromised SIM card can send AT commands to force arbitrary code execution, file exfiltration, and network degradation on connected devices. The study tested 26 devices using a new toolkit called CATana, finding vulnerabilities in several smartphones including the Oppo Find X5, Oppo Reno 14 F 5G, and Asus Zenfone 9, as well as multiple IoT modulators. Notably, the team achieved code execution on an Autel charging station equipped with a Quectel EC25-AFX module.

The issue stems from standard proactive SIM command specifications allowing RUN AT instructions, which vendors should disable or retire. Related fixes were issued for CVE-2025-48618 (Google) earlier, while current tracking identifiers include CVE-2026-57550 (Qualcomm) and CVD-2026-0122 (GSMA).