SIMCom SIM7600G Modem Undocumented Root Shell Access Vulnerability

Vulnerability

A vulnerability exists in the SIMCom SIM7600G modem, specifically in the firmware revision LE20B03SIM7600M21-A. The modem supports an undocumented AT command that allows an attacker to execute system commands with root privileges. Exploitation requires either physical access to the modem or remote shell access to a device that sends AT commands to the modem.

Impact

Exploitation of this vulnerability provides unauthorized root access on the affected modem, allowing for unrestricted execution of system commands.

Reproduction

The vulnerability can be reproduced by sending the undocumented AT command 'AT+CSHELL' through a tool like 'mmcli', which communicates with the modem. This command can be used to execute system commands on the modem with root privileges. For example, executing 'AT+CSHELL="id"' would return the user ID and group ID, confirming root access.

Remediation

As of now, there is no known patch for this vulnerability. Users are advised to contact their SIMCom representative or distributor to request a patch that removes the backdoor command.

Added: Jun 11, 2025, 9:27 AM
Updated: Jun 11, 2025, 9:27 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.6
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.