None
EN
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
['The Hacker News', 'Swati Khandelwal', 'Aug']
The Hacker News
A malicious SIM card can order the device it sits in to run commands of the attacker's choosing.
Unattended IoT gear with an accessible SIM tray and few other exposed interfaces is exactly where that trade is worth making.
Inside it, the Quectel EC25AFXDGA module's atfwd_daemon passes attacker-controlled text into a shell call through an unsafe format string.
Muench told The Hacker News the team disclosed to Quectel as the module vendor, which then notified its own customers.
The reports went to Google, Oppo, Quectel, Semtech and Qualcomm in March 2026, and to the GSMA in May.