Nine of 26 smartphones and cellular modules tested by researchers will blindly execute commands issued by a malicious SIM card, and on connected hardware the trick escalates to full code execution.
A team from the University of Birmingham and security firm Fuzzware built a toolkit called CATana and probed 18 phones and eight cellular IoT devices for a specification feature known as Proactive SIM. The function lets a card push commands to the modem, including RUN AT, which gives the SIM a direct line into AT command handling. Compliance was uneven: six of the eight IoT modules carried out the commands, and among phones the OPPO Find X5, OPPO Reno 14 F 5G, and ASUS Zenfone 9 were the only ones to respond out of 18 tested. No iPhone or Pixel responded.
The exposure matters most in machine-to-machine gear. Quectel supplied five of the six vulnerable modules; of those five, three were pulled from an EV charger, an industrial router, and a car telematics unit. On an AUTEL EV charger, SIM-issued commands triggered a command injection flaw in the modem’s Linux-based application processor, giving the researchers code execution. On an OPPO Reno 14 F 5G, the hostile card accepted 198 AT commands, including ones that power off the phone, stop the modem, or force the connection onto 2G.
Because 2G lacks network-to-device authentication, a device dragged onto the older network becomes more vulnerable to rogue base stations. The team also demonstrated file theft against a Quectel EG25-G modem.
The technique only works when a malicious card is already seated, whether swapped in by hand, slipped in as a thin interposer, or subverted during manufacturing. No real-world exploitation of the interface has surfaced so far. The researchers were told by Qualcomm about a hardened configuration that leaves the interface disabled by default; Quectel, for its part, reports the file-access flaw is fixed. Fleet operators should ask suppliers whether RUN AT ships enabled in their firmware.
