Affected Systems
Cellular IoT modules (6 of 8 tested, primarily Quectel parts with Qualcomm processors) in EV chargers, industrial routers, car telematics units. Limited phone impact: OPPO Find X5, OPPO Reno 14 F 5G, ASUS Zenfone 9. Attack requires physical SIM access or supply chain compromise. No CVE assigned.
Exploitation Status
No active exploitation reported. Proof-of-concept demonstrated by University of Birmingham researchers on commercial Autel EV charger (model MAXI US AC W12-L-4G) and Quectel modules. Tooling (CATana) publicly released.
Business Impact
Attackers with physical SIM access or supply chain position can achieve full device compromise on vulnerable IoT cellular modules. Demonstrated impacts include arbitrary code execution, persistent 2G downgrade (enabling fake base station attacks), file exfiltration, and device shutdown. Unattended IoT deployments with accessible SIM trays face highest risk. No vendor advisories published; Quectel vulnerability portal requires login. Qualcomm states hardened configuration available but not deployed retroactively by default.
Urgency
🟡 Within a week
Recommended Actions
- Contact cellular module suppliers (especially Quectel, Qualcomm-based products) to confirm if RUN AT proactive command is enabled in deployed firmware and request immediate disablement
- Audit physical security of IoT devices with cellular connectivity; restrict SIM tray access on EV chargers, industrial routers, telematics units, and similar unattended equipment
- Review supply chain controls for SIM card provisioning to detect potential interposer insertion or operator compromise
- Monitor for unexplained 2G network downgrades or modem resets on cellular IoT fleets as potential indicators of SIM-based attacks
- For affected Quectel modules (EC25AFXDGA, EG25-G series), apply firmware updates when available and verify RUN AT interface is disabled, not just mitigated
