CVE-2025-26412
Undocumented Root Shell Access in SIMCom SIM7600G Modem
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.8EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
11 Jun 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The SIMCom SIM7600G modem supports an undocumented AT command, which allows an attacker to execute system commands with root permission on the modem. An attacker needs either physical access or remote shell access to a device that interacts directly with the modem via AT commands.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
SIMCom · SIM7600G ModemWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →