Find notable cyber news and cases, enriched with sources, timelines, and signals.

Qualcomm/Quectel SIM proactive AT interface code execution flaw (CVE-2026-57550)

Vulnerability
First reported
Last updated
Happening score
H score 10
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-57550 tracks a SIM proactive AT interface flaw in Qualcomm/Quectel cellular modules that lets a hostile SIM push commands into modem firmware and reach code execution. Researchers found the capability enabled on 9 of 26 devices and demonstrated takeover on a commercial Autel EV charger. The affected surface includes Quectel EC25/EG25/RM52xN modules and some phones that accepted RUN AT. No attacks have been reported, and vendors are relying on mitigation and hardened defaults rather than a single universal patch.

Related Happenings

Autel MaxiCharger AC Elite Home 40A NFC-triggered buffer overflow security flaw

Vulnerability
H score0 First: 23.01.2026 23:04 Last: 23.01.2026 23:04 Sources 1

About this happening: A buffer overflow in the Autel MaxiCharger AC Elite Home 40A was demonstrated as a device-takeover path, exposing an exploitable weakness in an EV charger. The exploit...

Timeline

  1. 11.08.2026 15:05 2 articles · 2h ago

    Researchers demonstrate RUN AT code execution on a commercial Autel EV charger

    Technical Analysis Update

    Researchers at the University of Birmingham and Fuzzware tested 26 phones and cellular modules for the SIM proactive RUN AT capability, found it enabled in 9 devices, and used it to run their own code on a commercial Autel EV charger; among the phones tested, only the OPPO Find X5, the OPPO Reno 14 F 5G, and the ASUS Zenfone 9 accepted the command, and every accepting device ran a Qualcomm communication processor.

    Show sources