PT-2025-25199 · Simcom · Simcom Sim7600G

Constantin Schieber-Knöbl

+2

·

Published

2023-11-20

·

Updated

2025-06-18

·

CVE-2025-26412

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SIMCom SIM7600G modem (affected versions not specified)
Description The issue concerns an undocumented AT command in the SIMCom SIM7600G modem, allowing an attacker to execute system commands with root permission on the modem. This can be achieved with either physical access or remote shell access to a device that interacts directly with the modem via AT commands. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Hidden Functionality

Weakness Enumeration

Related Identifiers

BDU:2026-00054
CVE-2025-26412

Affected Products

Simcom Sim7600G