Henri Carnot, Avantix and EURECOM; Aurélien Francillon, EURECOM
Cellular basebands are critical components in mobile devices, enabling connectivity with cellular networks. Their notorious complexity, proprietary design, insufficient security hardening, and support for multiple generations of complex cellular protocols make them a prime target for attacks. Although billions of devices rely on these components, and despite the many papers published in recent years, baseband security remains poorly explored. This paper provides a systematization of knowledge on baseband security, analyzing prior work on vulnerability discovery and attack surfaces. We present a taxonomy of vulnerabilities, review state-of-the-art analysis techniques, including static analysis, over-the-air testing, and emulation, and discuss their respective strengths and limitations. Finally, we outline promising research directions to address gaps in current methodologies. Our goal is to provide a comprehensive framework that guides future work and strengthens the security of cellular ecosystems.