Executive Summary
In August 2026, researchers from the University of Birmingham and security firm Fuzzware discovered that malicious SIM cards can execute attacker-controlled commands within the modems of cellular IoT devices, such as electric vehicle chargers, industrial routers, and car telematics units. Testing 26 devices, they found that 9 were vulnerable, including certain models from OPPO and ASUS. The vulnerability stems from the 'RUN AT' proactive command, which allows a SIM card to instruct the modem to execute AT commands, potentially leading to full device compromise. This issue predominantly affects machine-to-machine hardware, with several Quectel modules identified as susceptible. The researchers recommend disabling or hardening the 'RUN AT' interface to mitigate this risk.
This discovery underscores the critical need for robust security measures in IoT devices, especially as they become more integrated into essential infrastructure. The ability for a SIM card to control device modems highlights a significant attack vector that could be exploited if not properly addressed.
Why This Matters Now
The increasing deployment of IoT devices in critical infrastructure makes them attractive targets for cyberattacks. This vulnerability demonstrates how a seemingly innocuous component like a SIM card can be weaponized to compromise entire systems, emphasizing the urgency for manufacturers to implement stringent security protocols and for operators to ensure their devices are updated and configured securely.
Attack Path Analysis
An attacker inserts a malicious SIM card into an IoT device, exploiting the device's firmware to execute unauthorized commands. This leads to the attacker gaining elevated privileges, allowing control over the device's functions. The attacker then moves laterally to other connected devices within the network. Establishing a command and control channel, the attacker maintains persistent access. Sensitive data is exfiltrated from the compromised devices. Finally, the attacker disrupts device operations, causing service outages.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
An attacker inserts a malicious SIM card into an IoT device, exploiting the device's firmware to execute unauthorized commands.
Related CVEs
CVE-2026-57550
CVSS 8.8A vulnerability in certain Qualcomm communication processors allows malicious SIM cards to execute arbitrary AT commands, potentially leading to unauthorized code execution on affected devices.
Affected Products:
Quectel EC25 – All versions
Quectel EG25-G – All versions
Quectel RM52xN – All versions
OPPO Find X5 – All versions
OPPO Reno 14 F 5G – All versions
ASUS Zenfone 9 – All versions
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
SIM Card Swap
Scheduled Task/Job
Screen Capture
SMS Control
Software Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Device Security
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Automotive
Malicious SIM cards can execute attacker commands on car telematics units and EV chargers, enabling vehicle takeover through compromised cellular modules.
Utilities
Electric vehicle charging infrastructure vulnerable to SIM-based attacks allowing remote code execution and complete device compromise through cellular IoT modules.
Telecommunications
Cellular IoT devices and industrial routers susceptible to hostile SIM proactive commands, enabling lateral movement and egress security bypasses.
Consumer Electronics
Mobile devices including OPPO and ASUS handsets vulnerable to permanent network downgrades and unauthorized modem control via malicious SIM cards.
Sources
- A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Deviceshttps://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.htmlVerified
- WOOT '26 Presentation: Exploiting SIM Card Interfaces in Cellular IoT Deviceshttps://www.usenix.org/conference/woot26/presentation/lisowskiVerified
- NVD Entry for CVE-2026-57550https://nvd.nist.gov/vuln/detail/CVE-2026-57550Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Implementing Aviatrix Zero Trust CNSF would likely reduce the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit the device's firmware may be constrained by enforcing strict identity-based access controls and continuous verification of device behavior.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could be limited by enforcing strict segmentation policies that restrict access to sensitive device functions.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement may be constrained by continuous monitoring and control of east-west traffic, reducing the ability to reach other devices.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command and control channels could be reduced by comprehensive visibility and control over network traffic across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts may be limited by enforcing strict egress policies that monitor and control outbound data flows.
The attacker's ability to disrupt device operations could be reduced by limiting access to critical functions and continuously monitoring device behavior.
Impact at a Glance
Affected Business Functions
- Device Control Systems
- Data Transmission
- Remote Monitoring
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive operational data and control over IoT devices.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict device-to-device communication and limit lateral movement.
- • Deploy East-West Traffic Security controls to monitor and control internal network traffic, detecting unauthorized movements.
- • Utilize Multicloud Visibility & Control to gain comprehensive insights into network activities and identify anomalies.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent unauthorized data exfiltration.
- • Apply Inline IPS (Suricata) to detect and prevent known exploit patterns and malicious payloads.



