Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Quectel

Quectel Vendor Cyber Rating & Cyber Score

quectel.com

Quectel’s passion for a smarter world drives us to accelerate IoT innovation. A highly customer-centric organization, we are a global IoT solutions provider backed by outstanding support and services. Our growing global team of over 4,000 professionals sets the pace for innovation in cellular, GNSS, Smart and WiFi/BT modules and antennas. Listed on the Shanghai Stock Exchange (603236.SS), our international leadership is devoted to advancing IoT across the globe. For technical support, please contact our FAE via [email protected]; for business issues, please contact our sales team via [email protected]


Quectel A.I CyberSecurity Scoring

Quectel
Company Information
Website:https://www.quectel.com/
Employees number:969
Number of followers:214,475
NAICS:517
Industry Type:Telecommunications
Homepage:quectel.com
Quectel Risk Score (AI oriented)
Between 750 and 799
logo
QuectelTelecommunications
Updated:
11/08/2026
761/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Quectel Global Score (TPRM)
xxxx
logo
QuectelTelecommunications
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Quectel
QuectelFair
Current Score
761Baa (FAIR)
01000
1 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
761Before Incident
JULY 2026
761Before Incident
JUNE 2026
761Before Incident
MAY 2026
763Before Incident
Vulnerability
01 May 2026Quectel
Quectel and Semtech: Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G

Malicious SIM Cards Exploit Proactive Functionality to Hijack Devices

760After Incident
CRITICAL-3
SEMQUE1786444258
Malicious SIM Cards Exploit Proactive Functionality to Hijack Devices Researchers from the University of Birmingham and Fuzzware have uncovered critical vulnerabilities in how SIM cards interact with smartphones and IoT devices, enabling attackers to execute code, steal data, or force devices onto insecure 2G networks. The findings, presented at the USENIX WOOT conference in Baltimore, highlight risks in proactive SIM functionality a feature designed to let SIMs issue commands to their host devices. Using a toolkit called CATANA, the team led by Tomasz Piotr Lisowski, Marius Muench, and Kristian Covic tested 26 devices (18 smartphones and 8 IoT modems). Nine devices exposed an AT command interface to the SIM, with IoT modems being particularly vulnerable (seven of eight tested). The attacks exploited RUN AT, a command that allows SIMs to execute legacy AT instructions, originally designed for modems in the 1980s. Key vulnerabilities demonstrated include: - Code execution on an Autel EV charger via a Quectel EC25-AFX modem. - Denial-of-service attacks, including forcing an Oppo Reno14 F 5G to power down or lock onto 2G (a downgrade resistant to standard fixes like airplane mode). - File theft from a Quectel EG25-G modem by combining malicious symbolic links with SIM commands. - Unauthorized browser launches on vulnerable Android versions (CVE-2025-48618), patched in December 2025 for Android 13–16. The attacks require SIM control, achievable through compromised software, physical tampering, or supply chain manipulation. While modern smartphones have reduced exposure, IoT devices remain at higher risk. The researchers disclosed findings to Google, Oppo, Quectel, Semtech, Qualcomm, and the GSMA. Qualcomm now disables the SIM AT interface by default, and the GSMA tracks the issue as CVD-2026-0122. The team advocates retiring RUN AT and other high-risk proactive SIM features to mitigate long-term threats.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: File theft, unauthorized data accessSystems Affected: Smartphones, IoT modems, EV chargersDowntime: Denial-of-service (device power down, 2G network lock)Operational Impact: Device hijacking, network downgrade, unauthorized browser launchesIdentity Theft Risk: Potential (if PII was accessed)
DATA BREACH
Type Of Data Compromised: Files, device control dataSensitivity Of Data: Potentially high (if PII or system files were accessed)Data Exfiltration: Yes (file theft demonstrated)Personally Identifiable Information: Potential (not confirmed)
APRIL 2026
763Before Incident
MARCH 2026
763Before Incident
FEBRUARY 2026
763Before Incident
JANUARY 2026
763Before Incident
DECEMBER 2025
763Before Incident
NOVEMBER 2025
763Before Incident
OCTOBER 2025
763Before Incident
SEPTEMBER 2025
763Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Quectel ?
?
What was Quectel's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Quectel's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Quectel's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Quectel's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Quectel's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Quectel's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Quectel's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Quectel's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Quectel's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Quectel's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Quectel's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Quectel's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Quectel ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Quectel's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?