A rogue SIM card can commandeer its host device, including electric-vehicle chargers, industrial routers, and car telematics units. Of the six involved components, five are Quectel products, which include items taken from electric vehicle chargers, industrial routers, and automotive telematics units. Knowing the victim's number isn't enough; every attack begins with a hostile card already inserted into the slot, swapped by hand, slipped in as a thin interposer, pushed out by a compromised operator, or subverted through software or on the production line.

Marius Muench, an assistant professor in computer science at the University of Birmingham, stated in the university’s announcement of the research that the SIM's proactive capabilities and the attack surface it opens are "explicitly defined" in the technical specifications for cellular communication.

Architecture exacerbates vulnerabilities on the IoT side. The user is unable to resolve this issue by toggling airplane mode, switching to manual network selection, turning off mobile data, disabling the SIM card, or changing the preferred network generation in settings. A third case study exploited arbitrary file access through a TFTP daemon that ran as root without verifying paths are symbolic links.

Muench stated that the team is reasonably certain all modules within Quectel's EC25, EG25, and RM52xN series are impacted, anticipating it's likely other Quectel modules utilizing a Qualcomm modem will also be affected.