By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Malicious SIM Cards Can Execute Code in Cellular IoT Modems

A critical vulnerability has been identified that allows a malicious SIM card to execute arbitrary code on the cellular modems of Internet of Things (IoT) devices. Researchers from the University of Birmingham and the security firm Fuzzware demonstrated that this exploit can grant an attacker full control over the compromised device. The security flaw resides within the cellular modules that are integral to a wide range of IoT applications, including electric vehicle chargers, industrial routers, and vehicle telematics units. By sending specially crafted commands through a compromised SIM card, an attacker can effectively hijack the modem and, by extension, the entire device it powers.
The research team tested a total of 26 different phones and cellular modules to assess the prevalence and impact of this vulnerability. Their findings indicate that the exploit is not limited to a single manufacturer or model, suggesting a widespread risk across the IoT ecosystem. The attack vector involves exploiting the communication protocols between the SIM card and the modem. Typically, SIM cards are designed to hold authentication credentials and perform limited operations. However, this vulnerability allows for the injection of malicious commands that bypass standard security checks, enabling the execution of unauthorized code directly on the modem's firmware. This could lead to a complete takeover of the device, allowing attackers to manipulate its functions, exfiltrate sensitive data, or use the device as a pivot point for further network intrusion.
The implications of this discovery are significant, given the increasing reliance on cellular-connected IoT devices in critical infrastructure and everyday applications. For instance, an attacker gaining control of an electric vehicle charger could potentially disrupt charging services or even cause physical damage. In industrial settings, compromised routers could lead to the shutdown of essential operations or the theft of proprietary information. Vehicle telematics units, which often transmit location data and diagnostic information, could be used for surveillance or to disable vehicle safety features. The researchers highlighted that the vulnerability is particularly concerning because it leverages a component that is often overlooked in security audits – the SIM card itself.
While the specific technical details of the exploit were not fully disclosed in the initial announcement to prevent immediate exploitation, the researchers confirmed that the attack is achievable with a physically accessible SIM card slot. This means that an attacker would need to have physical access to the device or be able to swap out the legitimate SIM card with a malicious one. The security firms involved are working with manufacturers to develop patches and mitigation strategies. Users of IoT devices that rely on cellular connectivity are advised to remain vigilant and to apply any security updates provided by their device manufacturers as soon as they become available. Further details on the affected devices and the precise nature of the vulnerability are expected to be released following coordinated disclosure efforts.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.