CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

Rogue SIM cards hijack EV chargers through a hidden modem command

A hostile SIM card can command the modems inside EV chargers and car telematics units to run attacker code.

CarThreat Staff
Last updated: August 12, 2026 3:59 am
By
ctadmin
2 Min Read
SHARE

Researchers from the University of Birmingham and the firm Fuzzware demonstrated that a SIM card swapped into the right device can force the modem it sits in to run attacker-chosen commands. Their proof of concept executed custom code on a store-bought EV charger, and they say car telematics units face the same exposure.

The lever is RUN AT, an obscure feature that lets a card push instructions to the modem before the modem asks for anything. When enabled, it hands the SIM the modem’s AT command language, the control interface that chip vendors extend with their own commands. In a survey of 26 phones and cellular modules, nine devices accepted the instruction. Six of eight cellular modules did, including five Quectel parts drawn from an EV charger, an industrial router, and a vehicle telematics control unit. Only three of 18 phones did, all Android handsets.

All nine devices run Qualcomm communication processors, though five other Qualcomm phones rejected the command, a gap the paper attributes to vendor customization. Qualcomm says it has produced a hardened configuration that turns the interface off by default, and Quectel reports mitigating the file-access flaw while still working on the interface itself. Neither vendor has released an advisory, and no real-world exploitation has surfaced.

The card has to be in the slot to matter, which means a physical swap, a thin interposer, a corrupted carrier employee, or tampering on the production line. Unattended chargers with reachable SIM trays are the obvious target. The researchers want the interface hardened, deprecated, or removed, and advise fleet operators to ask suppliers whether RUN AT ships enabled in their firmware and whether it can be disabled.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Charging InfrastructureCybersecurityElectric Vehicles (EVs)Firmware SecurityRemote Code Execution (RCE)Telematics Control Units (TCU)Vulnerabilities
SOURCES:The Hacker News
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

Smart Edge Architecture Wins PlaxidityX vCore the AutoTech Cybersecurity Excellence Award

By
ctadmin
June 4, 2026
CybersecurityElectric VehiclesPolicy & Compliance

BYD OTA Update Sparks ‘Battery Lock’ Controversy as Israel Weighs New Connected Vehicle Rules

By
ctadmin
May 29, 2026
Cybersecurity

License plate camera firm locks down vehicle data after abuse reports

By
ctadmin
August 17, 2026
Policy & Compliance

Quebec report declares car data consent fundamentally broken

By
ctadmin
August 23, 2026
Cybersecurity

PlaxidityX vDome Wins CLEPA Innovation Award for Proactive Anti-Theft Tech

By
ctadmin
May 22, 2026
Cybersecurity

Infineon Pushes EV Inverter Thermal Limits With 205°C SiC Module

By
ctadmin
May 29, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?