Researchers from the University of Birmingham and security firm Fuzzware have uncovered a significant security vulnerability involving SIM cards. This flaw allows attackers to execute commands on devices equipped with certain cellular modules, including those used in electric vehicle chargers and industrial routers. The study’s findings raise concerns about the security of cellular IoT devices.
Research Findings on SIM Card Exploitation
The investigation tested 26 phones and cellular modules, discovering that nine devices were susceptible to remote code execution via the SIM card. Notably, six out of eight cellular modules accepted malicious commands, while only three out of eighteen phones did, specifically the OPPO Find X5, OPPO Reno 14 F 5G, and ASUS Zenfone 9. The vulnerability is predominantly found in machine-to-machine (M2M) hardware, with Quectel components being particularly affected.
The attack method requires an adversary to insert a compromised SIM card into the device. This can be done physically or through manipulation during the production process. Devices like unattended IoT systems with accessible SIM trays are especially at risk.
Technical Details and Vendor Responses
The vulnerability exploits a proactive SIM card command known as RUN AT, which instructs the modem to execute AT commands. These commands, part of the modem control protocol since the 1980s, provide a broad attack surface for malicious activity. The research highlights that the architecture of these IoT devices, often running Android on ARM processors, is particularly vulnerable.
Qualcomm and Quectel have acknowledged the issue, with Qualcomm developing a hardened configuration to disable the interface by default. However, neither company has released a public advisory. The researchers recommend disabling the vulnerable interface to mitigate risks, though no attacks exploiting this vulnerability have been reported yet.
Impact on IoT Devices and Future Mitigations
The broader implications of this vulnerability are significant, as affected modules are used in various IoT devices, including vehicle chargers and payment terminals. The researchers’ survey suggests that several Quectel modules are compromised, and the company has yet to make firmware updates publicly available, complicating the verification process.
The findings have been communicated to major stakeholders such as Google, Oppo, Qualcomm, and the GSMA. Qualcomm has assigned the issue CVE-2026-57550, though it is not yet listed in the CVE Program. While some companies have committed to addressing the issue, public advisories are still lacking.
This situation underscores the need for robust security protocols in the growing IoT landscape. As device manufacturers work on solutions, users are advised to consult their module suppliers about potential vulnerabilities and available updates.
