Qualcomm/Quectel SIM proactive AT interface code execution flaw (CVE-2026-57550)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-57550 tracks a SIM proactive AT interface flaw in Qualcomm/Quectel cellular modules that lets a hostile SIM push commands into modem firmware and reach code execution. Researchers found the capability enabled on 9 of 26 devices and demonstrated takeover on a commercial Autel EV charger. The affected surface includes Quectel EC25/EG25/RM52xN modules and some phones that accepted RUN AT. No attacks have been reported, and vendors are relying on mitigation and hardened defaults rather than a single universal patch.
Related Happenings
Autel MaxiCharger AC Elite Home 40A NFC-triggered buffer overflow security flaw
Vulnerability
H score0
First: 23.01.2026 23:04
Last: 23.01.2026 23:04
Sources 1
About this happening:
A buffer overflow in the Autel MaxiCharger AC Elite Home 40A was demonstrated as a device-takeover path, exposing an exploitable weakness in an EV charger. The exploit...
Autel MaxiCharger AC Elite Home 40A NFC-triggered buffer overflow security flaw
VulnerabilityAbout this happening: A buffer overflow in the Autel MaxiCharger AC Elite Home 40A was demonstrated as a device-takeover path, exposing an exploitable weakness in an EV charger. The exploit...
Timeline
-
11.08.2026 15:05 2 articles · 2h ago
Researchers demonstrate RUN AT code execution on a commercial Autel EV charger
Technical Analysis UpdateResearchers at the University of Birmingham and Fuzzware tested 26 phones and cellular modules for the SIM proactive RUN AT capability, found it enabled in 9 devices, and used it to run their own code on a commercial Autel EV charger; among the phones tested, only the OPPO Find X5, the OPPO Reno 14 F 5G, and the ASUS Zenfone 9 accepted the command, and every accepting device ran a Qualcomm communication processor.
Show sources
- A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices — thehackernews.com — 11.08.2026 15:05
- A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices — thehackernews.com — 11.08.2026 15:05