Your SIM Card Could Be Hacked Into a Weapon, Researchers Reveal a Shocking New Threat

Security flaw found in cellular modems which allows a hostile SIM card to give commands to the modem. This security flaw will pose threats to electric-vehicle charging stations, industrial routers, and other cellular IoT devices.
SIM Cards Can Access Modem Commands
The team at the University of Birmingham and Fuzzware cybersecurity firm evaluated 26 phones and cellular modules. They discovered that nine units had the possibility of accepting a functionality that enables SIM cards to direct the modem to perform commands.
Six out of eight tested cellular modules accepted the ability, while three out of 18 smartphones were able to accept the feature. The devices impacted include OPPO Find X5, OPPO Reno 14 F 5G and ASUS Zenfone 9. None of the tested iPhones or Google Pixel devices accepted the command.
They discovered that five out of six impacted modules were produced by Quectel. These modules have been seen in electric vehicle chargers, industrial routers, and vehicle telematics control units.
The RUN AT Feature Creates an Attack Path
The problem is based on a proactive SIM command named RUN AT. It enables the SIM card to instruct a modem to issue an AT command, which is a language of modem control.
The functionality is defined in the existing cellular specifications and not some anomaly from them. Yet, it is believed by the researchers that enabling the SIM card to access a generic modem command interface might be very dangerous in terms of security.
The majority of tested modules come with a small application processor, which enables running of additional software along with the cellular radio.
Researchers Demonstrate Code Execution on EV Charger
In a particular demonstration, the researchers exploited a vulnerable command-handling mechanism in the Autel EV charger equipped with a Quectel EC25AFXDGA module. It helped them circumvent the character filter and finally run their code.
In another example, an OPPO Reno 14 F 5G was demonstrated to be tricked into connecting to 2G via a malicious SIM card. This condition cannot be easily reversed using the regular features of the phone. The lack of mutual authentication on 2G makes it possible to conduct a fake cell tower attack.
The researchers managed to find yet another instance in which any files can be accessed from a Quectel EG25-G module.
Vendors Are Working on Fixes
Qualcomm created a hardened version which turns off the interface as the default setting. Quectel stated that it has fixed the file access problem and will continue to fix the interface itself.
The researchers advise hardening, deprecating, or turning off the interface. They have made their testing software public and available, CATana.
These vulnerabilities were reported to Google, OPPO, Quectel, Semtech, Qualcomm and GSMA in 2026. The SIM AT interface is known for CVE-2026-57550 and GSMA identification CVD-2026-0122. No exploits on the interface have been reported yet.
Business News
From Army Veteran to Award-Winning Entrepreneur: Danielle King’s Inspiring Rise to Success
Amazon Business Hits $60 Billion, How Agentic AI Is Revolutionizing B2B Procurement
How Community Bank Delaware’s $1,000 Donation Is Strengthening the Future of Lewes Firefighters
Autodesk Just Launched a Game-Changing Program Every Small Business Should Know About
Rice University's Historic New Business Hall Is Set to Transform the Future of Business Education




















