CVE-2025-26412: Simcom SIM7600G Modem
Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.
The SIMCom SIM7600G modem supports an undocumented AT command, which allows an attacker to execute system commands with root permission on the modem. An attacker needs either physical access or remote shell access to a device that interacts directly with the modem via AT commands.
Affected products
- Simcom SIM7600G Modem
Published 2025-06-11. Last modified 2026-06-17.