Executive Summary

In August 2026, researchers from the University of Birmingham and security firm Fuzzware discovered that malicious SIM cards can execute attacker-controlled commands within the modems of cellular IoT devices, such as electric vehicle chargers, industrial routers, and car telematics units. Testing 26 devices, they found that 9 were vulnerable, including certain models from OPPO and ASUS. The vulnerability stems from the 'RUN AT' proactive command, which allows a SIM card to instruct the modem to execute AT commands, potentially leading to full device compromise. This issue predominantly affects machine-to-machine hardware, with several Quectel modules identified as susceptible. The researchers recommend disabling or hardening the 'RUN AT' interface to mitigate this risk.

This discovery underscores the critical need for robust security measures in IoT devices, especially as they become more integrated into essential infrastructure. The ability for a SIM card to control device modems highlights a significant attack vector that could be exploited if not properly addressed.

Why This Matters Now

The increasing deployment of IoT devices in critical infrastructure makes them attractive targets for cyberattacks. This vulnerability demonstrates how a seemingly innocuous component like a SIM card can be weaponized to compromise entire systems, emphasizing the urgency for manufacturers to implement stringent security protocols and for operators to ensure their devices are updated and configured securely.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The vulnerability affects certain cellular IoT devices, including specific models from OPPO and ASUS, as well as several Quectel modules used in electric vehicle chargers, industrial routers, and car telematics units.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Implementing Aviatrix Zero Trust CNSF would likely reduce the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to exploit the device's firmware may be constrained by enforcing strict identity-based access controls and continuous verification of device behavior.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges could be limited by enforcing strict segmentation policies that restrict access to sensitive device functions.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's lateral movement may be constrained by continuous monitoring and control of east-west traffic, reducing the ability to reach other devices.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish and maintain command and control channels could be reduced by comprehensive visibility and control over network traffic across cloud environments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's data exfiltration efforts may be limited by enforcing strict egress policies that monitor and control outbound data flows.

Impact (Mitigations)

The attacker's ability to disrupt device operations could be reduced by limiting access to critical functions and continuously monitoring device behavior.

Impact at a Glance

Affected Business Functions

  • Device Control Systems
  • Data Transmission
  • Remote Monitoring
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive operational data and control over IoT devices.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict device-to-device communication and limit lateral movement.
  • Deploy East-West Traffic Security controls to monitor and control internal network traffic, detecting unauthorized movements.
  • Utilize Multicloud Visibility & Control to gain comprehensive insights into network activities and identify anomalies.
  • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent unauthorized data exfiltration.
  • Apply Inline IPS (Suricata) to detect and prevent known exploit patterns and malicious payloads.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image