# The SIM Card in Your EV Charger Can Be Turned Against You
For four decades, the SIM card's job description has been simple: sit there, prove who you are, and answer when asked. Researchers from the University of Birmingham and security firm Fuzzware just demonstrated that on a significant slice of deployed cellular IoT hardware, the SIM can do something rather different — reach out and run code on the device it inhabits.
The attack, presented this week at USENIX WOOT in Baltimore, exploits a proactive command called RUN AT. Instead of waiting passively to be read, a SIM with this capability can push instructions *back* at the modem. RUN AT specifically tells the modem to execute an AT command — the control language invented for the Hayes Smartmodem in 1981 and still baked into every cellular module shipped today, often with proprietary extensions that expand what an attacker can do.
Supporting RUN AT therefore hands any card in the slot a general-purpose command console.
## Six of Eight Modules, Five of Them Quectel
The team tested 26 devices: 18 smartphones and 8 dedicated cellular modules. Nine accepted the command. On the consumer side, only three phones were vulnerable: the OPPO Find X5, the OPPO Reno 14 F 5G, and the ASUS Zenfone 9. No iPhone. No Pixel. The exposure is concentrated elsewhere.
Six of the eight modules tested accepted RUN AT. Five of those six were made by Quectel — parts pulled from a commercial EV charger, an industrial router, and a car telematics control unit. That is not a coincidence of sampling. Quectel commands a substantial share of the global cellular module market, and its hardware is embedded in exactly the unattended, difficult-to-patch equipment that makes this class of attack worth attempting.
The researchers did not stop at proof-of-concept. They ran their own code on a real commercial EV charger. The writeup calls the module's internal architecture "a rich attack surface to hostile SIMs" — because the modem doesn't just pass AT commands to the radio. It forwards unhandled commands up to a small application processor, usually an ARM Cortex-A7 running Android, sitting alongside the radio. The SIM ends up talking to a Linux computer. A full takeover of that machine — and by extension whatever network it connects to — becomes a reachable outcome.
## What the Attack Requires — and Why That's Not Reassuring
There is a significant caveat the researchers are careful about: the attack starts with a hostile SIM already in the slot. You cannot execute RUN AT over the air against a victim device with a legitimate card in it. The attacker needs to either swap the physical card, slip a thin interposer between the existing SIM and the reader, compromise an operator who can push a hostile profile, or get to the hardware somewhere on the supply chain before it ships.
That threat model sounds exotic. For consumer smartphones, it largely is. For unattended industrial hardware sitting in a parking garage, a roadside cabinet, or a trucking depot — hardware with an accessible SIM tray, minimal physical security, and an interface that runs AT commands to a Linux computer — the calculus looks different. Physical access to industrial IoT gear is easier to arrange than most defenders assume, and operator compromise is not a theoretical threat in geopolitically contested environments.
## A Standard Feature With No Standard Off Switch
The part that makes this hard to fix is that RUN AT is not a bug in the usual sense. As Marius Muench, the Birmingham professor who led the work, put it, the SIM's proactive capability and the attack surface it creates are "explicitly defined in the technical specifications for cellular communication." The interface is compliant with the standard. That means there is no CVE to patch and no single vendor to blame.
Every nine affected devices ran a Qualcomm communication processor. Five other Qualcomm-based handsets in the survey did not accept the command — the researchers attribute this to vendor customization. Qualcomm says it has a hardened configuration that disables the interface by default, and that configuration will ship on future devices and reach existing modules via updates. Quectel says it has fixed the associated file-access flaw and is working on the interface itself.
Neither company has published a public advisory. Quectel's vulnerability portal requires a login even to view disclosures.
For fleet operators who cannot wait for a firmware cycle, the researchers offer one concrete step available right now: ask your module supplier whether RUN AT is enabled in the firmware you're running and whether it can be turned off. That is an embarrassingly low bar for a disclosure involving demonstrated code execution on production industrial hardware.
No attacks exploiting this interface have been reported.
---
## HackWire Analysis
This research lands at an uncomfortable moment for cellular IoT security. The industry spent the last several years cleaning up plaintext protocols, default credentials, and shodan-exposed management interfaces. What this paper demonstrates is that the attack surface extends down to a layer most defenders never consider — the SIM itself, and specifically its ability to initiate, not just respond.
The Quectel concentration should be read carefully. This is not a fringe vendor. Quectel modules are in utility meters, fleet vehicles, industrial controllers, and EV charging networks across the world. When you find a vulnerability pattern in five out of six tested Quectel parts, you are describing a systemic condition in a market leader's product line, not an edge case.
The supply-chain vector deserves more attention than it's getting. Nation-state actors with access to mobile network operators — a realistic capability for several major intelligence services — could theoretically push hostile SIM profiles without ever touching the physical hardware. The researchers' threat model mentions this possibility and then moves on. The security community should not.
For defenders, the action items split across two timelines. Immediately: audit firmware versions, query your module supplier about RUN AT status, and inventory any unattended cellular IoT hardware with accessible SIM trays. Medium-term: watch for Qualcomm's hardened configuration to propagate through the Quectel firmware update cycle, then verify that RUN AT code paths are actually removed rather than merely switched off — the researchers themselves flagged uncertainty on that point.
The broader lesson is one the IoT security community keeps relearning: the attack surface is always larger than the feature list. AT commands are 45 years old. The SIM proactive command set is 30. Both were designed for different threat environments, and both are now load-bearing infrastructure in hardware that controls physical systems. The gap between "this is in the spec" and "this is safe" has always been where the interesting vulnerabilities live.
— HackWire Editorial
---
## Related Coverage