Researchers from the University of Birmingham and the firm Fuzzware demonstrated that a SIM card swapped into the right device can force the modem it sits in to run attacker-chosen commands. Their proof of concept executed custom code on a store-bought EV charger, and they say car telematics units face the same exposure.
The lever is RUN AT, an obscure feature that lets a card push instructions to the modem before the modem asks for anything. When enabled, it hands the SIM the modem’s AT command language, the control interface that chip vendors extend with their own commands. In a survey of 26 phones and cellular modules, nine devices accepted the instruction. Six of eight cellular modules did, including five Quectel parts drawn from an EV charger, an industrial router, and a vehicle telematics control unit. Only three of 18 phones did, all Android handsets.
All nine devices run Qualcomm communication processors, though five other Qualcomm phones rejected the command, a gap the paper attributes to vendor customization. Qualcomm says it has produced a hardened configuration that turns the interface off by default, and Quectel reports mitigating the file-access flaw while still working on the interface itself. Neither vendor has released an advisory, and no real-world exploitation has surfaced.
The card has to be in the slot to matter, which means a physical swap, a thin interposer, a corrupted carrier employee, or tampering on the production line. Unattended chargers with reachable SIM trays are the obvious target. The researchers want the interface hardened, deprecated, or removed, and advise fleet operators to ask suppliers whether RUN AT ships enabled in their firmware and whether it can be disabled.