Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Vulnerable SIM Cards Threaten Cellular IoT Security

Vulnerable SIM Cards Threaten Cellular IoT Security

Posted on August 11, 2026 By CWS

Researchers from the University of Birmingham and security firm Fuzzware have uncovered a significant security vulnerability involving SIM cards. This flaw allows attackers to execute commands on devices equipped with certain cellular modules, including those used in electric vehicle chargers and industrial routers. The study’s findings raise concerns about the security of cellular IoT devices.

Research Findings on SIM Card Exploitation

The investigation tested 26 phones and cellular modules, discovering that nine devices were susceptible to remote code execution via the SIM card. Notably, six out of eight cellular modules accepted malicious commands, while only three out of eighteen phones did, specifically the OPPO Find X5, OPPO Reno 14 F 5G, and ASUS Zenfone 9. The vulnerability is predominantly found in machine-to-machine (M2M) hardware, with Quectel components being particularly affected.

The attack method requires an adversary to insert a compromised SIM card into the device. This can be done physically or through manipulation during the production process. Devices like unattended IoT systems with accessible SIM trays are especially at risk.

Technical Details and Vendor Responses

The vulnerability exploits a proactive SIM card command known as RUN AT, which instructs the modem to execute AT commands. These commands, part of the modem control protocol since the 1980s, provide a broad attack surface for malicious activity. The research highlights that the architecture of these IoT devices, often running Android on ARM processors, is particularly vulnerable.

Qualcomm and Quectel have acknowledged the issue, with Qualcomm developing a hardened configuration to disable the interface by default. However, neither company has released a public advisory. The researchers recommend disabling the vulnerable interface to mitigate risks, though no attacks exploiting this vulnerability have been reported yet.

Impact on IoT Devices and Future Mitigations

The broader implications of this vulnerability are significant, as affected modules are used in various IoT devices, including vehicle chargers and payment terminals. The researchers’ survey suggests that several Quectel modules are compromised, and the company has yet to make firmware updates publicly available, complicating the verification process.

The findings have been communicated to major stakeholders such as Google, Oppo, Qualcomm, and the GSMA. Qualcomm has assigned the issue CVE-2026-57550, though it is not yet listed in the CVE Program. While some companies have committed to addressing the issue, public advisories are still lacking.

This situation underscores the need for robust security protocols in the growing IoT landscape. As device manufacturers work on solutions, users are advised to consult their module suppliers about potential vulnerabilities and available updates.

The Hacker News Tags:cellular modules, Cybersecurity, IoT devices, IoT security, M2M hardware, Qualcomm, Quectel, security research, SIM vulnerability, Telecommunications

Post navigation

Previous Post: Ghostjacking Threat: AI Coding Agents at Risk
Next Post: Corma Secures $60M to Enhance Cybersecurity with AI

Related Posts

Microsoft Alerts on OAuth Redirect Exploitation in Phishing Attacks Microsoft Alerts on OAuth Redirect Exploitation in Phishing Attacks The Hacker News
Windows Shell Vulnerability Exploited, Microsoft Confirms Windows Shell Vulnerability Exploited, Microsoft Confirms The Hacker News
CISA Flags Meteobridge CVE-2025-4008 Flaw as Actively Exploited in the Wild CISA Flags Meteobridge CVE-2025-4008 Flaw as Actively Exploited in the Wild The Hacker News
PoisonSeed Hackers Bypass FIDO Keys Using QR Phishing and Cross-Device Sign-In Abuse PoisonSeed Hackers Bypass FIDO Keys Using QR Phishing and Cross-Device Sign-In Abuse The Hacker News
New Browser Security Report Reveals Emerging Threats for Enterprises New Browser Security Report Reveals Emerging Threats for Enterprises The Hacker News
Nation-State Hacks, Spyware Alerts, Deepfake Malware, Supply Chain Backdoors Nation-State Hacks, Spyware Alerts, Deepfake Malware, Supply Chain Backdoors The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Polygon Blockchain for Stealth Malware
  • OpenAI Launches GPT-5.6-Cyber for Advanced Cybersecurity
  • Mozilla Revokes Key After Private Repo Leak
  • Horizon3 Boosts Partner Growth with $20M Investment
  • Corma Secures $60M to Enhance Cybersecurity with AI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Polygon Blockchain for Stealth Malware
  • OpenAI Launches GPT-5.6-Cyber for Advanced Cybersecurity
  • Mozilla Revokes Key After Private Repo Leak
  • Horizon3 Boosts Partner Growth with $20M Investment
  • Corma Secures $60M to Enhance Cybersecurity with AI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark