Security researchers have discovered that attackers can deploy malicious SIM cards to execute arbitrary code on cellular modems embedded in critical infrastructure devices. The attack targets the firmware of cellular modules rather than the SIM itself, allowing remote command execution on devices like EV chargers, industrial routers, and vehicle telematics systems.
Researchers from the University of Birmingham and Fuzzware tested 26 phones and cellular modules, identifying vulnerabilities that allow SIM cards to trigger modem firmware execution. This creates a direct path for attackers to compromise entire devices without requiring separate exploits.
The threat affects any system relying on embedded cellular connectivity. EV charging networks become vulnerable to operational disruption or data theft. Industrial routers controlling manufacturing plants can be hijacked to alter network traffic or deny service. Car telematics units, used for GPS tracking and diagnostic reporting, expose vehicle location data and operational parameters to attackers.
The attack vector is particularly dangerous because SIM card provisioning happens at the carrier or MVNO level, giving attackers multiple insertion points. A compromised SIM reaches the target device through normal activation channels. Once active, the malicious SIM sends commands that the modem firmware processes without proper validation.
The vulnerability stems from inadequate input validation in modem firmware. Many manufacturers fail to sanitize SIM-originated commands, treating them as inherently trustworthy. This assumption breaks down when attackers compromise SIM issuance processes or physical supply chains.
Organizations running IoT deployments with cellular connectivity should audit their modem firmware versions and seek patches from manufacturers. Carriers can implement additional validation on SIM card provisioning systems. Device manufacturers must implement command validation within modem firmware regardless of signal source.
The broader implication extends beyond individual devices. Critical infrastructure operators relying on cellular IoT for remote monitoring and control face operational risk if modems become compromised. Vehicle manufacturers with connected car
