Executive Summary
Recent research by the University of Birmingham and Fuzzware has revealed a critical vulnerability in the way certain cellular IoT devices handle SIM card commands. A malicious SIM card can execute attacker-controlled code inside the modems of affected devices, including electric vehicle (EV) chargers, industrial routers, and automotive telematics units. This report details the technical aspects, exploitation scenarios, affected devices, and references for further investigation.
Threat Actor Profile
As of August 2026, there is no public attribution to specific APT groups or targeting of particular sectors or countries. However, the nature of the vulnerability makes it especially relevant to: - Critical Infrastructure: Electric vehicle (EV) charging networks, industrial automation, and automotive telematics. - IoT Deployments: Payment terminals, industrial routers, and embedded systems using affected cellular modules. - Global Exposure: Devices using Quectel and Qualcomm-based modules are deployed worldwide.
Technical Analysis of Malware/TTPs
Vulnerability Overview
- Vulnerability Name: Malicious SIM Card Code Execution in Cellular IoT Modems
- CVE Identifiers:
- CVE-2026-57550 (SIM AT interface exposure, assigned via Qualcomm)
- CVD-2026-0122 (GSMA tracking)
- CVE-2025-48618 (related Android web page auto-launch, Google December 2025)
- CVE-2021-31698 (prior related AT command injection in Quectel modules)
- Affected Vendors: Primarily Quectel (EC25, EG25, RM52xN series), Qualcomm-based modules, OPPO, ASUS (specific models), and potentially others using similar architectures.
- Attack Vector: Physical or supply-chain insertion of a malicious SIM card, or remote compromise of SIM/eSIM provisioning.
Attack Mechanism
- Proactive SIM Commands: The SIM card can send "proactive commands" to the modem, including the RUN AT command, which allows the SIM to instruct the modem to execute arbitrary AT commands.
- AT Command Execution: AT commands are a legacy control language for modems, extended by vendors. If the modem passes these commands to an application processor (often running Linux/Android), the SIM effectively gains a general-purpose shell.
- Exploitation Examples:
- EV Charger Takeover: On a commercial Autel MAXI US AC W12-L-4G charger (Quectel EC25AFXDGA module), researchers achieved code execution by exploiting a format string vulnerability in the atfwd_daemon, bypassing a character blocklist with a newline character.
- Smartphone Downgrade: On OPPO Reno 14 F 5G, the command AT+COPS=0,,,0 forced the device to 2G-only mode, which cannot be reversed by the user, exposing the device to fake base station attacks.
- File Exfiltration: On Quectel EG25-G, a TFTP daemon running as root allowed arbitrary file reads via symbolic links, with exfiltration using AT+QSMTP commands.
- Other Attacks: Re-enabling debug interfaces, exfiltrating device identifiers, sending SMS/calls, shutting down modems, and disabling cellular connectivity.
Affected Devices
- Tested and Vulnerable:
- 6/8 cellular modules (5 Quectel, 1 other) accepted the malicious command.
- 3/18 smartphones: OPPO Find X5, OPPO Reno 14 F 5G, ASUS Zenfone 9.
- Not Vulnerable: iPhones, Google Pixel devices (for this specific attack vector).
- IoT Focus: EV chargers, industrial routers, automotive telematics, payment terminals, and other embedded systems using affected modules.
Exploitation in the Wild
- No confirmed in-the-wild exploitation as of August 2026.
- Attack Prerequisites: Attacker must insert a malicious SIM (physical access, supply chain, or operator compromise).
- Threat Scenarios:
- Physical SIM swap or implant.
- Compromised operator provisioning.
- Supply-chain manipulation during manufacturing/distribution.
- Remote exploitation of SIM/eSIM management vulnerabilities.
Victimology and Targeting
- Critical Infrastructure: Electric vehicle charging networks, industrial automation, and automotive telematics are at risk due to widespread use of affected modules.
- IoT Deployments: Payment terminals, industrial routers, and embedded systems using Quectel/Qualcomm-based modules are globally exposed.
- No evidence of targeted attacks as of August 2026, but the attack surface is broad and global.
Mitigation and Countermeasures
- For IoT Fleet Operators: Contact your module supplier to determine if the RUN AT interface is enabled and if it can be disabled in your firmware.
- For Device Manufacturers: Apply available firmware updates from module vendors; request hardened configurations.
- For Security Teams: Monitor for the following IOCs:
- Device stuck in 2G mode (cannot be reverted by user).
- Unexpected device shutdowns or loss of cellular connectivity.
- Unusual AT command logs (if accessible).
- Unexpected file exfiltration via TFTP or SMTP from modem modules.
- Re-enabled debug interfaces or unauthorized SMS/call activity.
References
- The Hacker News
- University of Birmingham
- USENIX WOOT 2026 - CATANA Paper
- Reddit - r/SecOpsDaily
- HelpNetSecurity
- CATana Toolkit
About Rescana
Prepared by Rescana OSINT Cybersecurity Research Team For further details or incident response support, contact your Rescana representative.



