Researchers from the University of Birmingham and Fuzzware disclosed that malicious or compromised SIM cards can abuse standards-compliant SIM Toolkit features, including Proactive SIM and RUN AT, to send AT commands directly to modems in some smartphones and cellular IoT devices. Testing with the CATana toolkit found exposed SIM-to-modem command interfaces on a subset of 26 devices, including multiple Qualcomm-based and Quectel-powered designs, enabling attacks such as arbitrary file reads, denial of service, forced shutdowns, persistent downgrades from 5G to 2G, and in some cases code execution. Demonstrated targets included an Autel EV charger using a Quectel EC25-AFX module, an OPPO Reno14 F 5G, and a Quectel EG25-G modem.
The broader modem interface issue is being tracked as CVE-2026-57550 and GSMA CVD-2026-0122, while a related Android flaw that let a hostile SIM open an attacker-controlled website without user interaction was tracked as CVE-2025-48618 and patched by Google for Android 13 through 16 in December 2025. Qualcomm said it offers a hardened configuration that disables the SIM AT interface by default, and Quectel said it mitigated one file-access flaw and had fixed command injection in newer firmware. The researchers warned that vendor-by-vendor fixes may not be enough and urged deprecation of the RUN AT feature to reduce the attack surface across phones, EV chargers, industrial routers, and vehicle telematics systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
SC Media reported a vulnerability tracked as CVE-2026-57550 that lets a malicious or compromised SIM issue attacker-chosen AT commands through the SIM Toolkit RUN AT capability on certain phones and cellular modules. Researchers said 9 of 26 tested devices were vulnerable, including Quectel modules and specific OPPO and ASUS models, with impacts ranging from device takeover to loss of cellular connectivity and fake base station attacks.
The researchers reported the wider issue to the GSMA after contacting affected vendors. The broader ecosystem issue was then taken up for industry tracking.
The researchers disclosed their findings to Google, Oppo, Quectel, Semtech, and Qualcomm. This vendor-coordination step covered vulnerabilities uncovered through abuse of proactive SIM and RUN AT functionality.
The GSMA began tracking the broader malicious-SIM issue as CVD-2026-0122. Multiple reports describe this as the industry coordination identifier for the exposed SIM AT attack surface.
Google fixed the Android issue tracked as CVE-2025-48618 in Android 13, 14, 15, and 16. The flaw allowed a hostile SIM to trigger LAUNCH BROWSER and open an attacker-controlled website without user interaction, including while the phone was locked.
Quectel said it fixed the separate exploit that allowed arbitrary file reading and exfiltration from the EG25-G module when a specially prepared symbolic link existed. The company was still working on a fix for the broader open SIM AT interface issue.
Researchers from the University of Birmingham and Fuzzware presented findings showing that standards-compliant proactive SIM and RUN AT functionality can be abused to control some phones and cellular IoT devices. Their CATana testing found exposed AT command interfaces on a subset of 26 tested devices and demonstrated impacts including code execution, file theft, denial of service, and forced 2G downgrades.
Qualcomm produced a hardened configuration that disables the SIM AT interface by default. This was a mitigation response to the exposed attack surface identified by the researchers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcescworld.com
Open sourcehelpnetsecurity.com
Open sourcethehackernews.com
Open sourcetheregister.com
Open sourceusenix.org
Open sourceusenix.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.