A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
Researchers found that a malicious SIM card can execute attacker code in cellular modems of IoT devices, such as EV chargers and industrial routers, potentially taking full control of the device. The discovery was made after testing 26 phones and cellular modules.
A malicious SIM card can force cellular IoT devices—including EV chargers, industrial routers, and car telematics—to execute attacker commands, enabling full device takeover. Researchers from the University of Birmingham and security firm Fuzzware tested 26 phones and cellular modules and confirmed the vulnerability lies inside the device’s modem, allowing the SIM to run arbitrary code.