← back
CVE-2025-26412mediumCWE-912

Undocumented Root Shell Access in SIMCom SIM7600G Modem

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.8epss 0.3%
exploitation probability
0.3%top 80% of all CVEs
observed exploitation
nono source reports it
The SIMCom SIM7600G modem supports an undocumented AT command, which allows an attacker to execute system commands with root permission on the modem. An attacker needs either physical access or remote shell access to a device that interacts directly with the modem via AT commands.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
SIMCom · SIM7600G Modem