Quectel response to FCC about IoT module security
7.9.2023 16:03:00 EEST | Business Wire | Press release
Quectel Wireless Solutions, a global IoT solutions provider, today commented on the recent letter and response being published by the FCC and the Select Committee of the US Congress questioning if Quectel’s IoT modules represent a potential security risk.
“We welcome the opportunity to work with the FCC and other U.S. government entities to demonstrate our compliance and best practice device security approach, says Norbert Muhrer, President and CSO, Quectel Wireless Solutions. “We are committed to contributing to the advancement of a smarter world by delivering best-in-class and secure products. This commitment is evidenced by our extensive device OEM customer base and our constant focus on providing our customers with the best and most secure modules in the industry.”
The Select Committee to the US Congress’ letter to the FCC had several misconceptions about how Quectel modules work. Quectel’s clarification regarding the statements made in the letter is as follows.
Committee letter: “Connectivity modules are typically controlled remotely and are the necessary link between the device and the internet.”
Quectel’s U.S. customers or their customers’ third-party suppliers/service providers handle device and data management exclusively. Firmware updates are managed and controlled by the device original equipment manufacturer (OEM), not Quectel.
Committee letter: “Serving as the link between the device and the internet, these modules have the capacity both to brick the device and to access the data flowing from the device to the web server that runs each device”
The control of Quectel modules resides with the microcontroller unit (MCU) or central processing unit (CPU) embedded within the customer's device. Quectel itself does not possess any control; instead, this authority rests solely with the OEM – the entity responsible for developing the device. Remote management of the device is achievable solely through the OEM's device management platform. A notable instance of this, referred to in the letter, is the widely covered case involving John Deere agricultural equipment, where just the OEM typically can disable the equipment by accessing and shutting down its own MCU’s controlling the machine.
Committee letter: “As a result, if the CCP can control the module, it may be able to effectively exfiltrate data or shut down the IoT device.”
Once Quectel modules leave the factory and are delivered to its customers, Quectel customers own the data, and Quectel has no access to any of the data collected. The ownership, control, storage, and modification of the data generated by IoT devices within the market firmly rest with the OEM device makers and its customers. Even in the rare cases outside of the U.S. where Quectel resells the connectivity service of a wireless carrier, Quectel does not have access to the device data.
Committee letter: “This raises particularly grave concerns in the context of critical infrastructure and any type of sensitive data.”
Applications that require high security, such as critical infrastructure, typically use private access point names (APNs) and other methods which strictly control and monitor network access. This can be used to control and monitor any data flowing to and from the device. Critical infrastructure is meticulously fashioned with a multi-tiered security approach defined and implemented solely by the device OEM, not Quectel.
The cellular industry is heavily regulated and requires intensive testing and accreditation. Carrier and regulatory certifications are executed by trusted third-party labs and carrier labs, assuring that the module complies with strict technical requirements. The Quectel modules have obtained certifications from the FCC, PCS Type Certification Review Board (PTCRB) and major carriers throughout the world, which underlines Quectel’s commitment to meeting rigorous industry standards.
In addition to cellular modules, Quectel also provides Wi-Fi, Bluetooth and GNSS modules and antennas. As a GSMA member, Quectel and its carrier partners comply with all cellular industry regulations and applicable standards to ensure that end customer data is securely transmitted between customer device and mobile network operator. Quectel does not have access to ANY of the device data.
Quectel is committed to delivering high-quality, best-in-class, secure modules and go above and beyond industry standard practices by conducting independent third-party cyber security audits. More recently Quectel also retained the security firm Finite State, which is auditing and penetration testing the security of its modules through rigorous security testing, improved software supply chain visibility, and comprehensive software risk management. Quectel is also participating in the formulation of new industry security certification standards, such as the CTIA Cybersecurity Certification Working Group and pursuing additional cyber security certifications from various U.S. entities as new standards are formulated and adopted.
Qualcomm manufactures the chipsets and software platforms that are at the core of the Quectel modules. “Our Qualcomm partnership underlines the importance we place on working with well-trusted and secure partners from across the ecosystem to deliver high-quality solutions globally,” Mr. Muhrer continues. “Quectel's impact on the global IoT industry is profound. We supplied millions of cellular modules to support the distribution of Covid-19 vaccines for leading U.S. and global organizations including Pfizer, Johnson & Johnson, and other leading suppliers of vaccines. This underscores our commitment to playing a pivotal role in critical global initiatives.”
About Quectel
Quectel’s passion for a smarter world drives us to accelerate IoT innovation. A highly customer-centric organization, we are a global IoT solutions provider backed by outstanding support and services. Our growing global team of 5,900 professionals sets the pace for innovation in cellular, GNSS, Wi-Fi and Bluetooth modules as well as antennas and services.
With regional offices and support across the globe, our international leadership is devoted to advancing IoT and helping build a smarter world.
For more information, please visit: www.quectel.com, LinkedIn, Facebook, and X (formerly known as Twitter).
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20230907525548/en/
Contact information
Media contact: media@quectel.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Klarna Card reaches 5 million active customers19.3.2026 16:31:00 EET | Press release
Klarna, the global digital bank and payments provider, today announced that the Klarna Card has reached 5 million active customers globally, underscoring rapid adoption as consumers shift towards new forms of payment which provide more control over day-to-day money management. The card draws from the customer's own funds for everyday spending, with the option to spread the cost of a specific purchase, like a large appliance or a flight, when it makes sense to do so. The result is a card that offers genuine spending control without the long-term debt obligations that come with traditional credit cards. The card’s growth is reinforced by Klarna’s membership program. The program offers premium perks such as airport lounge access, travel insurance, and lifestyle subscriptions — without requiring users to take on debt, meet spending thresholds, or revolve balances. By separating everyday spending from rewards, Klarna is challenging the strings-attached model legacy banks have long relied on
Andersen Consulting Expands Technology Platform in France19.3.2026 15:30:00 EET | Press release
Andersen Consulting expands its digital transformation offering through a Collaboration Agreement with Teolia Consulting, a French firm specializing in project and product management, cloud platform engineering, data transformation, and Atlassian suite integration and adoption. Founded in 2014, Teolia Consulting helps organizations achieve digital performance, from agile methodology to time-to-market solutions. The firm’s expertise is focused on delivering integrated strategies that align technology with organizational change. The firm works across industries including banking, insurance, fashion, and retail, empowering clients to strengthen resilience and accelerate digital maturity. “At Teolia Consulting, we believe that true transformation happens when technology and people evolve together,” said Lucienne Jacquet, managing partner of Teolia. “By collaborating with Andersen Consulting, we not only amplify our impact but also gain access to a worldwide organization of like-minded indi
Stonebranch Releases 2026 Global State of IT Automation Report, Revealing Orchestration as the Missing Link for AI Adoption and Trust19.3.2026 15:30:00 EET | Press release
Stonebranch, a leading provider of service orchestration and automation solutions, today released its annual 2026 Global State of IT Automation Report, the company’s most comprehensive research study to date. Based on responses from 402 IT automation professionals spanning C-suite executives to individual contributors across North America, EMEA, Latin America, and APAC, the report provides a detailed, data-driven portrait of how enterprises are investing in, deploying, and deriving value from IT automation in 2026. “This year’s findings highlight an important shift in how organizations approach automation,” said Giuseppe Damiani, CEO of Stonebranch. “Organizations are now building automation as strategic infrastructure — a governed, scalable foundation that spans hybrid environments, operationalizes AI, and delivers automation-as-a-service to thousands of users across the enterprise. The companies that get orchestration right are not just running more efficient IT operations. They are
Perma-Pipe Accelerates Growth with New U.S. Northeast Facility Investment to serve Artificial Intelligence Data Center customers, Provides Middle East Operations’ Update and Concludes the Board’s Review of Strategic Alternatives19.3.2026 15:00:00 EET | Press release
Perma-Pipe International Holdings, Inc. (the “Company”) today announced a strategic expansion initiative focused on accelerating growth through entry into the high-demand U.S. Northeast region. The Company is positioning itself to capitalize on the rapidly expanding Artificial Intelligence (“AI”)-driven data center market in both the United States and international markets while continuing to reinforce its leadership in critical infrastructure solutions. As part of this growth strategy, Perma-Pipe will prioritize investments aimed at expanding its presence in the rapidly evolving AI data center sector. The initiative reflects the Company’s long-term commitment to supporting next-generation technology infrastructure and strengthening its position in the global energy, industrial, and infrastructure markets. Expansion in the U.S. Northeast President & Chief Executive Officer, Saleh Sagr said, “We are excited to announce the expansion of our operations with a new facility in the Northeast
Armis Launches First-of-Its-Kind Benchmark Report Warning of Critical Security Gaps in AI-Native Development19.3.2026 14:00:00 EET | Press release
Armis, the cyber exposure management & security company, is warning that the rapid enterprise adoption of AI-native development is outpacing critical security safeguards, leaving organizations exposed to systemic vulnerabilities. New research from Armis Labs’ Trusted Vibing Benchmark Report, which evaluates 18 leading generative AI models across 31 test scenarios, reveals a 100% failure rate in generating secure code. These vulnerabilities are most prevalent in high-risk areas like memory buffer overflows, design file uploads and authentication systems. Therefore, organizations should immediately implement AI-native application security controls to reduce risk. “The era of vibe coding is here, but speed should not come at the cost of security,” said Nadir Izrael, CTO and Co-Founder of Armis. “Our research finds that the worst offenders are the same ones selling security solutions for the very vulnerabilities their models create. If the industry continues to integrate autonomous code wi
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
