Researchers from the University of Birmingham and Fuzzware showed that a hostile SIM card could trigger modem commands on cellular IoT gear, with tests finding the feature active in 9 of 26 phones and modules and a live demonstration on a commercial EV charger.
The trick is that the SIM can send a proactive RUN AT command back into the modem, asking it to run AT commands, the control language modems use for their own management. On Quectel-built modules and some Qualcomm-based devices, that gives the card a local console inside the radio stack, so a physical SIM swap or interposer can reach code execution without touching the network first.
That shifts the trust boundary for machine-to-machine fleets: if the SIM tray is accessible, the attack path sits below remote defenses and can survive even when the device is otherwise isolated. The paper says five of the six affected modules were Quectel parts, including units pulled from an EV charger, an industrial router, and a telematics control unit.