VMTech
Discuss a project

Hostile SIM commands expose cellular IoT modules to code execution

Hostile SIM commands expose cellular IoT modules to code execution

Researchers at the University of Birmingham and security firm Fuzzware have shown that a malicious SIM card can send commands that lead to attacker-controlled code running inside cellular modems used by IoT equipment. In tests of 26 phones and cellular modules, nine accepted the SIM RUN AT command. Six of the eight cellular modules tested accepted it, and the team achieved code execution on a commercial Autel EV charger fitted with a Quectel EC25AFXDGA module.

The research focuses on cellular hardware in electric-vehicle chargers, industrial routers and vehicle telematics units. Of the six exposed modules, five were made by Quectel; three were recovered from an EV charger, an industrial router and a car telematics control unit. Only three of 18 phones accepted RUN AT: the OPPO Find X5, OPPO Reno 14 F 5G and ASUS Zenfone 9. No iPhone or Pixel in the sample did so.

A documented SIM capability becomes an attack interface

RUN AT is a proactive SIM command: rather than simply responding to requests from the modem, a SIM can instruct it to execute an AT command. AT commands are the long-established control language for modems, with vendor-specific extensions. When RUN AT is enabled, it can give a hostile card a route to the modem's control interface.

Marius Muench of the University of Birmingham said the proactive SIM capability is explicitly defined in cellular technical specifications. The issue is therefore not a departure from the standard, but vendors' decisions to expose and implement the interface. Every device that accepted the command used a Qualcomm communication processor, although five other Qualcomm-based handsets in the survey did not, which the paper attributes to vendor customisation.

The researchers presented the work at USENIX WOOT in Baltimore. Their findings arrive amid connected-system vulnerability exposure that also highlighted how vulnerabilities across connected systems can create operational exposure, while this case shows that a removable subscriber component may become the initial foothold.

Code execution on an EV charger

Inside the Autel MAXI US AC W12-L-4G charger, the Quectel module's atfwd_daemon passed attacker-controlled text to a shell call through an unsafe format string. A character blocklist was intended to stop shell escapes, but a newline bypassed it. The researchers reached code execution in two stages using commands issued by the SIM.

A separate Quectel EG25-G case involved arbitrary file reads through a root TFTP daemon that did not validate symbolic links, followed by exfiltration using the module's AT+QSMTP commands. That scenario additionally requires a malicious link to have been placed on the module filesystem through an SD card or a crafted partition.

On an OPPO Reno 14 F 5G, AT+COPS=0,,,0 forced the device onto 2G, a setting the researchers said the owner could not reverse through normal handset controls. Their CATana tooling identified 198 AT commands reachable through the SIM on that handset.

Supplier verification is the immediate action

Qualcomm said it has developed a hardened configuration that disables the interface by default. Quectel said it mitigated the file-access flaw and continues work on the interface, while confirming that the command injection was fixed in newer firmware without publishing affected or fixed versions. Semtech plans to ship Qualcomm-written patches. As of August 10, none of the five notified vendors had issued a public advisory, and no attacks have been reported.

For operators of cellular IoT fleets, the immediate business implication is to identify deployed module models and ask suppliers whether RUN AT is enabled in the delivered firmware, whether it can be disabled, and how verified updates can be provided for installed equipment.

#iotsecurity#mobilesecurity#cellularsecurity#embeddedsecurity
Open analytics
On the site 1 views
min read 4 12.08.2026
Instagram

Hostile SIM commands expose cellular IoT modules to code execution

Open the post on Instagram ↗