Malicious SIM Cards Can Execute Attacker Code on Cellular IoT Devices
Researchers have demonstrated that a malicious SIM card can force cellular IoT devices, such as EV chargers and industrial routers, to execute arbitrary attacker-chosen commands. This vulnerability, found in 26 tested phones and cellular modules, allows for full device takeover. The attack can also be triggered remotely via Plug and Play over Remote Desktop, posing a significant risk to critical infrastructure.