We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-26412

Undocumented Root Shell Access in SIMCom SIM7600G Modem



Description

The SIMCom SIM7600G modem supports an undocumented AT command, which allows an attacker to execute system commands with root permission on the modem. An attacker needs either physical access or remote shell access to a device that interacts directly with the modem via AT commands.

Reserved 2025-02-10 | Published 2025-06-11 | Updated 2025-06-11 | Assigner SEC-VLab

Problem types

CWE-912 Hidden Functionality

Product status

Default status
unknown

LE20B03SIM7600M21-A
affected

Credits

Constantin Schieber-Knöbl, SEC Consult Vulnerability Lab finder

Stefan Schweighofer, SEC Consult Vulnerability Lab finder

Steffen Robertz, SEC Consult Vulnerability Lab finder

References

r.sec-consult.com/simcom

cve.org (CVE-2025-26412)

nvd.nist.gov (CVE-2025-26412)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-26412

Support options

Helpdesk Chat, Email, Knowledgebase