started · updated
CATana vulnerability threatens billions of IoT and mobile devices
Researchers from the University of Birmingham and the company Fuzzware have identified a significant cybersecurity vulnerability known as ‘CATana’. The threat stems from the 45-year-old AT command standard, which is used for communication between computers and analog modules.
While originally designed for dial-up modems, these commands remain integrated into modern GSM, 4G, 5G, and IoT technologies to handle functions like SMS and signal strength checks. The vulnerability exploits the ‘Proactive SIM’ feature, which allows a SIM card to send commands directly to a device's modem.
During testing at the USENIX WOOT conference, researchers used CATana to target 26 devices, including 18 smartphones and 8 IoT systems such as connected car chargers and industrial solutions. The findings suggest that billions of devices, including critical infrastructure, could be at risk due to this long-standing communication protocol.