REVIEW 4 major objections 5 minor 85 references
Security Analysis of LTE Connectivity in Connected Cars: A Case Study of Tesla
T0 review · 4 major / 5 minor · reviewed 2026-08-04 · deepseek-v4-flash
Pith's one-line read This paper establishes that a wireless-only adversary with a rogue LTE base station can force Tesla vehicles to leak their SIM identity, camp on a fraudulent cell, and silently lose access to backend services, because the telematics unit's
desk verdict First systematic LTE attack battery on production Tesla TCUs with credible measurements—but the headline 'insecure fallback' claim is confounded by the authors disabling the eSIM in the very experiments where they report no fallback. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central object is the telematics control unit's LTE network-selection and attach state machine — the logic that decides which cell to camp on, how to answer NAS identity requests, when to retry attach, and when to fall back to WiFi or an alternate SIM profile. The argument turns on a two-stage whitelist: at the radio/attach stage the TCU accepts any PLMN, including test identifiers, while a backend 'roaming' gate filters data services only after attach and PDN setup, too late to stop control-plane attacks. The paper also relies on the modem's advertised capability set (support for GSM, legacy ciphers, null ciphering, silent SMS paths) as evidence of an enlarged attack surface.
What would settle it
A controlled drive-by experiment on a live commercial network: a rogue eNodeB advertising the vehicle's actual carrier PLMN at elevated power, with the car moving at speed and the real carrier cell still present. If the TCU either stays on the legitimate cell, or falls back to eSIM/WiFi within a few seconds of the rogue attach, the paper's DoS and fallback conclusions do not transfer to real driving conditions.
Extended reading notes
Core claim
The paper reports that a production Tesla's LTE connectivity behaves like an unusually permissive mobile device: it answers unprotected identity requests from a rogue base station that broadcasts the vehicle's real carrier PLMN, disclosing both IMSI and GUTI; it attaches to a spoofed cell even when the attacker cannot complete authentication, camping there with only partial connectivity; and under NAS rejections or data-plane blackouts it neither switches to the eSIM profile nor to WiFi, instead entering deterministic reattachment loops or indefinite partial states. It further reports that the TCU advertises legacy GSM/GPRS capabilities and null ciphering (while correctly rejecting null inte
Load-bearing premise
The headline results assume that behavior observed in a shielded testbed with SIM credentials the researchers themselves programmed — including the requirement that the rogue cell broadcast the vehicle's genuine carrier PLMN — is what a real adversary would encounter against live commercial networks.
Editorial extensions
If this is right
- A wireless-only attacker with a software-defined radio can provoke identity disclosure and persistent denial of service without any code execution, simply by spoofing the vehicle's carrier PLMN.
- Vehicles can be parked in a partial-attach state where backend services go dark, with no fallback to eSIM or WiFi and no driver alert, blocking OTA updates and remote commands.
- The same telematics behavior implies compliance gaps against UN R155/R156 and ISO/SAE 21434, particularly around OTA availability, user awareness, and DoS resilience.
- Because the modem and baseband stack are third-party components, the exposure is likely shared by other OEMs using the same hardware.
- Silent acceptance of SMS and emergency broadcasts means injected messages can act on the vehicle without any trace visible to the driver.
Reading between the lines
- Editorial inference: The attack's practical reach may be narrower than the headline suggests — real-world cell selection with vehicles in motion and operator-side defenses could break the PLMN-matching requirement; a reasonable next test is a drive-by experiment against a live carrier.
- Editorial inference: The absence of any UI alert for SMS/ETWS may be a deliberate product decision (e.g., alerts routed to the phone app), so the security question is whether any hidden handler exists; exposing TCU logging would settle it.
- Editorial inference: If regulators adopt the paper's mapping, type-approval audits may start requiring evidence of fallback behavior, not just protocol conformance.
- Editorial inference: A direct comparison with current smartphones under the same testbed would isolate vehicle-specific failures from generic LTE weaknesses; the paper did not run that comparison.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper presents a black-box LTE security evaluation of Tesla Model 3 and Cybertruck telematics units, conducted inside a 93 dB shielded enclosure using Amarisoft and srsRAN LTE stacks, programmable SIMs, and Tesla diagnostic interfaces (Toolbox/Service Mode). The authors report that the TCU discloses IMSI/GUTI when a rogue eNodeB broadcasts a matching PLMN, attaches partially to rogue cells and fails to recover, shows no fallback to eSIM/WiFi under control-plane, PDN, and routing failures, and silently accepts SMS and ETWS/CMAS messages without user-facing alerts. The paper maps these findings to UN R155/R156 and proposes mitigations such as stricter PLMN whitelisting, disablement of legacy ciphers/SMS, and better fallback logic.
Significance. If the headline findings are supported, this is a valuable early controlled study of automotive TCU behavior against known LTE attacks: the empirical setup is credible, with two independent LTE stacks, reference-device validation, 10 trials per configuration, direct TCU state observation, and a clear non-invasive methodology. The disclosure to Tesla and use of Consumer Reports vehicles with consent are also positive features. However, the paper's contribution is in large part a transfer of known LTE attacks to a vehicular context, and its strongest availability/fallback and silent-SMS claims are not fully supported by the reported experiments. With re-scoping and additional controls, the study could serve as a useful case study for the automotive cellular-security community.
major comments (4)
- [Appendix B.V; Table 3; §5 'Fallback and Partial States Flaws'] The no-fallback-to-eSIM result is a setup artifact. Appendix B.V states that after inserting the custom SIM, the authors 'explicitly disabled eSIM functionality' through Tesla Toolbox, and Appendix B.I notes the default eSIM is prioritized. Table 3 then reports 'Fallback triggered: No' across control-plane, PDN, and routing failures, and §5 states the TCU never switched to the eSIM profile. Observing no eSIM fallback after the experimenter disabled the eSIM is tautological. The FBS and partial-attach tests (Table 2, Figure 5) used the same pSIM-only configuration, so the claimed DoS 'blocking backend services' also does not test the production eSIM-primary configuration. The abstract's 'insecure fallback mechanisms' and the R156 recovery/user-awareness mapping are therefore not established as reported. The WiFi-fallback part may be non-tautological, but Table 3 aggregates eSIM and WiFi i
- [Abstract; §5 'SMS and Emergency Issues'] The abstract claims 'silent SMS injection' and 'broadcast message spoofing without driver awareness,' but the experiments show protocol-level delivery of well-formed text SMS over IMS and absence of UI display, not injection of silent/binary SMS or any demonstrable system-side effect. The paper concedes the silence 'may be intentional' and does not show that the TCU processed the ETWS/CMAS content beyond base-station acknowledgment. As a security claim, this is a UI-transparency observation with latent risk, not a demonstrated vulnerability. Please align the abstract and §5 terminology with the actual evidence, and either provide evidence of a concrete processing path or clearly label this as an unverified latent risk.
- [§6 'Regulatory Implications'; Table 4] The paper states that the experiments 'reveal several violations' of UN R155/R156 and Table 4 maps each observed behavior to a violation. This is too categorical. R155 is risk-based and allows OEMs to manage residual risk through their cybersecurity management system; R156 7.2.2.2 concerns user notification before/after software updates, which were not exercised in any of the reported tests. Observed protocol behaviors can inform risk assessments, but the paper does not show that Tesla's actual OTA process, user-notification flow, or CSMS documentation violates the regulations. Please rephrase the regulatory discussion as 'threats to the security objectives referenced by R155/R156' rather than as demonstrated non-compliance.
- [Table 2; §5 'False Base Station Susceptibility'] The quantitative DoS/recovery claims are setup-dependent in a way that should be stated in the main text, not only in a caveat. The observed 'failure to reattach to the legitimate network' occurred while the attacker's cell continued to transmit at high gain; this is an expected consequence of PLMN-priority cell selection when the rogue cell remains dominant, and it does not measure recovery after the attacker disappears. The paper's Figure 5 shows backend failure in the authors' own core with the attacker cell present, but no measurement is reported of how quickly the vehicle returns to service when the rogue cell is removed. The 90–100% attach success and 4-second connection durations are also explicitly acknowledged to depend on the experimental setup. Please separate the robust finding ('TCU attaches to a stronger cell broadcasting a permitted PLMN') from the setup-specific claims ab
minor comments (5)
- [Table 1] The table's most important condition is that IMSI/GUTI disclosure occurred only when the rogue eNodeB broadcast a PLMN matching the vehicle's current SIM (310260 or 310150). This should be prominent in the main text, as it tempers the 'lack of effective defenses' wording: the result confirms the known LTE behavior that a UE will answer an identity request from a cell it has selected, not a Tesla-specific weakness.
- [Abstract and terminology] The paper uses 'silent SMS injection' and 'insecure fallback mechanisms' in the abstract, but the body is more measured ('may be intentional,' 'latent risk'). Please make the abstract match the body's confidence level.
- [Figures 5, 15, 16] The traffic captures are hard to interpret without annotations. In particular, Figure 15 should mark which IP addresses are Tesla backend endpoints and which are testbed-local, and Figure 16 should be labeled with the NAS/RRC message names. This would improve reproducibility for readers who cannot access the raw logs.
- [§3 'Vehicles Under Test'] The paper says 'The tested vehicles were the Tesla Model 3 and Cybertruck (U.S. region 2024)' but does not give software versions or precise testing dates. Since firmware updates can change behavior, please provide the vehicle firmware versions and testing window, as far as the black-box access allows.
- [§6 'Cellular Connectivity in Other Automobiles'] The generalizability claims for other OEMs rest on the cited modem-supplier disclosure (Qualcomm/Quectel) and on casual inspection of other vehicles, not on comparable testing. This is fine as a hypothesis, but the wording should acknowledge that no equivalent experiments were performed on non-Tesla vehicles.
Circularity Check
Partial circularity: the 'no eSIM fallback' result is an artifact of the authors having explicitly disabled the eSIM before the fallback tests.
-
self definitional
[Appendix B.V 'Configuring the Vehicle' (Accessing Configurations & Debugging) and §5 'Fallback and Partial States Flaws']
"By default, Tesla prioritizes its internal eSIM over the physical SIM slot. Using Tesla Toolbox, we accessed the network configuration settings and explicitly disabled eSIM functionality, forcing the vehicle to utilize the physical SIM. ... In no instance did the TCU revert to alternative connectivity options, such as switching to the eSIM profile."
The paper's headline claim of 'insecure fallback mechanisms' is supported by the observation that, under control-plane, PDN, and routing failures, the TCU never fell back to the eSIM profile. But all fallback experiments were run after the experimenters had explicitly disabled the eSIM via Tesla Toolbox. The observed absence of eSIM fallback is therefore entailed by the experimental configuration: the alternative was removed by the authors before the test. This makes the claim 'no fallback to eSIM' equivalent to the setup input 'eSIM disabled', not an independent vehicle property. Since this fallback/no-fallback finding feeds directly into Table 3, the Abstract, and the R155/R156 regulatory conclusions about lack of recovery, this pillar of the paper's contribution is partially circular, e
full rationale
The core of the paper is black-box empirical testing against an externally configured LTE testbed, not a derivation from the paper's own assumptions. The IMSI catching, rogue base station, PLMN whitelisting, and SMS/ETWS injection results are direct observations of TCU behavior under controlled adversarial conditions and do not reduce to the paper's inputs. The frequent self-citations (Bitsikas & Pöpper, Freaky Leaky SMS) are background support for known cellular attack classes and are not load-bearing for the new claims. The one significant circular step is the fallback pillar: the paper concludes that Tesla's TCU lacks fallback to the eSIM profile, but Appendix B.V states that the authors explicitly disabled eSIM functionality via Tesla Toolbox before the pSIM-based tests. The 'no eSIM fallback' observation is therefore a tautology of the experimental setup, not a discovered vehicle deficiency. This affects the Abstract's 'insecure fallback mechanisms' claim, Table 3's fallback row, and the associated R155/R156 recovery conclusions. Because this is one of the paper's central contributions but not the whole paper, the overall circularity score is partial rather than total.
Assumptions & free parameters
assumptions (4)
- domain assumption The Amarisoft Callbox and srsRAN + USRP B210 stacks faithfully emulate a real LTE RAN/EPC, so TCU behavior observed against them indicates behavior against commercial networks.
- domain assumption 3GPP LTE protocol design: the network is not cryptographically authenticated before the UE answers IdentityRequests and performs initial attach; disclosing IMSI to an unauthenticated network that broadcasts a matching PLMN is standard-compliant behavior.
- ad hoc to paper Absence of UI display of SMS/ETWS messages implies the TCU 'silently processes' them, and silent processing is a latent security/safety vulnerability.
- domain assumption Tesla's acknowledgment that the modem is a third-party component (Qualcomm/Quectel) is sufficient to conclude the vulnerabilities are systemic across OEMs.
Cite this review
Pith. "Pith review of Security Analysis of LTE Connectivity in Connected Cars: A Case Study of Tesla." pith.science (2026). https://pith.science/paper/NBMMOKZ2
@misc{pith2026251022024,
author = {Pith},
title = {Pith review of: Security Analysis of LTE Connectivity in Connected Cars: A Case Study of Tesla},
year = {2026},
howpublished = {\url{https://pith.science/paper/NBMMOKZ2}},
note = {Machine review of arXiv:2510.22024}
}
read the original abstract
Modern connected vehicles rely on persistent LTE connectivity to enable remote diagnostics, over-the-air (OTA) updates, and safety-relevant services. While mobile network vulnerabilities are well documented in the smartphone ecosystem, their impact in safety-relevant automotive settings remains insufficiently examined. We conduct a black-box case study of LTE security in Tesla's Model 3 and Cybertruck, revealing systemic protocol weaknesses and architectural misconfigurations in connected vehicles. We find that Tesla's telematics stack is susceptible to IMSI catching, rogue base station hijacking, and insecure fallback mechanisms that may silently degrade service availability. Furthermore, legacy control-plane configurations allow for silent SMS injection and broadcast message spoofing without driver awareness. While the vulnerabilities are grounded in Tesla, this case study suggests broader implications for connected-vehicle telematics and for regulatory frameworks such as ISO/SAE 21434 and UN R155/R156, which assume secure, traceable, and resilient telematics in modern vehicles.
Figures
Figures from the paper (12 more)
Reference graph
Works this paper leans on
-
[1]
Digital cellular telecommunications system (phase 2+) (gsm); universal mobile telecommunications system (umts); lte; 5g; num- bering, addressing and identification
3rd Generation Partnership Project. Digital cellular telecommunications system (phase 2+) (gsm); universal mobile telecommunications system (umts); lte; 5g; num- bering, addressing and identification. Technical Report 23.003, 3GPP, 09 2024. Version 18.7.0
2024
-
[2]
Lte; general packet radio service (gprs) enhancements for evolved universal terrestrial radio access network (e-utran) access
3rd Generation Partnership Project. Lte; general packet radio service (gprs) enhancements for evolved universal terrestrial radio access network (e-utran) access. Tech- nical Report 23.401, 3GPP, 01 2025. Version 18.8.0
2025
-
[3]
Study on 5G security enhancements against False Base Stations (FBS)
3rd Generation Partnership Project (3GPP). Study on 5G security enhancements against False Base Stations (FBS). Technical Report 33.809, 3GPP, June 2019
2019
-
[4]
Compre- hensive LTE/5G Testing Solution
Amarisoft.Amarisoft Callbox Classic, 2025. Compre- hensive LTE/5G Testing Solution
2025
-
[5]
About lockdown mode
Apple Inc. About lockdown mode. https://support. apple.com/en-us/105120, 2025
2025
-
[6]
Cryptanalysis of the GPRS encryption algorithms GEA-1 and GEA-2
Christof Beierle, Patrick Derbez, Gregor Leander, Gaë- tan Leurent, Håvard Raddum, Yann Rotella, David Rup- precht, and Lukas Stennes. Cryptanalysis of the GPRS encryption algorithms GEA-1 and GEA-2. Cryptology ePrint Archive, Paper 2021/819, 2021
2021
-
[7]
Don’t hand it over: Vulnerabilities in the handover procedure of cellu- lar telecommunications
Evangelos Bitsikas and Christina Pöpper. Don’t hand it over: Vulnerabilities in the handover procedure of cellu- lar telecommunications. InACSAC ’21: Annual Com- puter Security Applications Conference, Virtual Event, USA, December 6 - 10, 2021, pages 900–915. ACM, 2021
2021
-
[8]
You have been warned: Abusing 5g’s warning and emergency systems
Evangelos Bitsikas and Christina Pöpper. You have been warned: Abusing 5g’s warning and emergency systems. InAnnual Computer Security Applications Conference, ACSAC 2022, Austin, TX, USA, December 5-9, 2022, pages 561–575. ACM, 2022
2022
Show all 85 references
-
[9]
Freaky leaky SMS: Extracting user locations by analyzing SMS timings
Evangelos Bitsikas, Theodor Schnitzler, Christina Pöp- per, and Aanjhan Ranganathan. Freaky leaky SMS: Extracting user locations by analyzing SMS timings. In32nd USENIX Security Symposium (USENIX Secu- rity 23), pages 2151–2168, Anaheim, CA, August 2023. USENIX Association
2023
-
[10]
Amplifying threats: The role of Multi-Sender coordination in SMS-Timing- Based location inference attacks
Evangelos Bitsikas, Theodor Schnitzler, Christina Pöp- per, and Aanjhan Ranganathan. Amplifying threats: The role of Multi-Sender coordination in SMS-Timing- Based location inference attacks. In18th USENIX WOOT Conference on Offensive Technologies (WOOT 24), pages 59–73, Phila...
2024
-
[11]
Tesla model 3 ranked least reliable ev in used car testing by tuv
CarExpert. Tesla model 3 ranked least reliable ev in used car testing by tuv. https://www.carexpert.co m.au/car-news/tesla-model-3-ranked-least-r eliable-ev-in-used-car-testing, 2025
2025
-
[12]
CellMapper Project.CellMapper: Cellular Network Mapping Tool, 2025
2025
-
[13]
Adrian Dabrowski, Nicola Pianta, Thomas Klepp, Mar- tin Mulazzani, and Edgar R. Weippl. Imsi-catch me if you can: Imsi-catcher-catchers.Proceedings of the 30th Annual Computer Security Applications Confer- ence, 2014
2014
-
[14]
An overview of attacks and defences on intelligent connected vehicles, 2019
Mahdi Dibaei, Xi Zheng, Kun Jiang, Sasa Maric, Robert Abbas, Shigang Liu, Yuexin Zhang, Yao Deng, Sheng Wen, Jun Zhang, Yang Xiang, and Shui Yu. An overview of attacks and defences on intelligent connected vehicles, 2019
2019
-
[15]
A practical-time attack on the a5/3 cryptosystem used in third generation GSM telephony
Orr Dunkelman, Nathan Keller, and Adi Shamir. A practical-time attack on the a5/3 cryptosystem used in third generation GSM telephony. Cryptology ePrint Archive, Paper 2010/013, 2010
2010
-
[16]
Cybersecurity challenges in vehicular communications.Vehicular Communications, 23:100214, 2020
Zeinab El-Rewini, Karthikeyan Sadatsharan, Daisy Flora Selvaraj, Siby Jose Plathottam, and Prakash Ranganathan. Cybersecurity challenges in vehicular communications.Vehicular Communications, 23:100214, 2020
2020
-
[17]
Connected cars and sustainability: How 5G enables a cleaner future
Ericsson. Connected cars and sustainability: How 5G enables a cleaner future. https://www.ericsson.c om/en/blog/2020/8/connected-cars-and-susta inability, 2020. Ericsson Blog
2020
-
[18]
Adaptover: Adaptive overshadowing attacks in cellular networks
Simon Erni, Martin Kotuliak, Patrick Leu, Marc Roeschlin, and Srdjan Capkun. Adaptover: Adaptive overshadowing attacks in cellular networks. MobiCom ’22, page 743–755, New York, NY , USA, 2022. Associ- ation for Computing Machinery
2022
-
[19]
Software-Defined Radio (SDR) for LTE/5G Research
Ettus Research, A National Instruments Brand.Ettus Research USRP B210, 2025. Software-Defined Radio (SDR) for LTE/5G Research. 14
2025
-
[20]
Future of smart connected vehicles
Expert Market Research. Future of smart connected vehicles. https://www.expertmarketresearch.c om/featured-articles/future-smart-connect ed-vehicles, 2025
2025
-
[21]
Iso 26262:2018 – road vehicles – functional safety
International Organization for Standardization. Iso 26262:2018 – road vehicles – functional safety. In- ternational Standard, 2018
2018
-
[22]
GNU Project.Ping: Network Diagnostic Tool, 2025
2025
-
[23]
GNU Project.Traceroute: Network Diagnostic Tool, 2025
2025
-
[24]
New tesla key card vulnerability lets hack- ers silently steal your ride
Dan Goodin. New tesla key card vulnerability lets hack- ers silently steal your ride. https://arstechnica.co m/information-technology/2022/06/new-tesla -key-card-vulnerability-lets-hackers-silen tly-steal-your-ride/, 2022
2022
-
[25]
Android 14 introduces first-of- its-kind cellular security enhancements
Google Security Blog. Android 14 introduces first-of- its-kind cellular security enhancements. https://se curity.googleblog.com/2023/08/android-14-i ntroduces-first-of-its-kind.html, 2023
2023
-
[26]
Keeping your android device safe from emerging cellular threats
Google Security Blog. Keeping your android device safe from emerging cellular threats. https://securi ty.googleblog.com/2024/08/keeping-your-and roid-device-safe-from.html, 2024
2024
-
[27]
This bluetooth attack can steal a tesla model X in minutes
Andy Greenberg. This bluetooth attack can steal a tesla model X in minutes. https://www.wired.com/stor y/tesla-model-x-hack-bluetooth/, 2021
2021
-
[28]
Tesla’s next car will seamlessly unlock with UWB, FCC leak suggests
Sean Hollister. Tesla’s next car will seamlessly unlock with UWB, FCC leak suggests. https://www.thever ge.com/2024/05/11/tesla-ultra-wideband-uwb -fcc-filing, 2024
2024
-
[29]
Guti reallocation demystified: Cellular location tracking with changing temporary identifier
Byeongdo Hong, Sangwook Bae, and Yongdae Kim. Guti reallocation demystified: Cellular location tracking with changing temporary identifier. InNetwork and Distributed System Security Symposium, 01 2018
2018
-
[30]
Privacy attacks to the 4g and 5g cellular paging protocols using side channel in- formation
Syed Hussain, Mitziu Echeverria, Omar Chowdhury, Ninghui Li, and Elisa Bertino. Privacy attacks to the 4g and 5g cellular paging protocols using side channel in- formation. InNetwork and Distributed System Security Symposium, 01 2019
2019
-
[31]
Lteinspector: A systematic approach for adversarial testing of 4g lte
Syed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, and Elisa Bertino. Lteinspector: A systematic approach for adversarial testing of 4g lte. InNetwork and Distributed System Security Symposium, 2018
2018
-
[32]
Select Fabricators Inc.Faraday Tents and Custom RF Shielded Enclosures, 2024
2024
-
[33]
Tesla ranks among least reliable used car brands in the u.s
InsideEVs. Tesla ranks among least reliable used car brands in the u.s. https://insideevs.com/news/7 31559/tesla-least-reliable-used-car-brand s/, 2025
2025
-
[34]
Iso/sae 21434: Road vehicles — cybersecurity engineering
International Organization for Standardization (ISO) and Society of Automotive Engineers (SAE). Iso/sae 21434: Road vehicles — cybersecurity engineering. Technical report, ISO/SAE, 2021
2021
-
[35]
Lte security, protocol exploits and location tracking experimentation with low-cost software radio, 2016
Roger Piqueras Jover. Lte security, protocol exploits and location tracking experimentation with low-cost software radio, 2016
2016
-
[36]
Never let me down again: Bidding- down attacks and mitigations in 5g and 4g
Bedran Karakoc, Nils Fürste, David Rupprecht, and Katharina Kohls. Never let me down again: Bidding- down attacks and mitigations in 5g and 4g. InPro- ceedings of the 16th ACM Conference on Security and Privacy in Wireless and Mobile Networks, WiSec ’23, 2023
2023
-
[37]
Touching the untouchables: Dynamic security analysis of the lte control plane
Hongil Kim, Jiho Lee, Eunkyu Lee, and Yongdae Kim. Touching the untouchables: Dynamic security analysis of the lte control plane. In2019 IEEE Symposium on Security and Privacy (SP), pages 1153–1168, 2019
2019
-
[38]
LTrack: Stealthy tracking of mobile phones in LTE
Martin Kotuliak, Simon Erni, Patrick Leu, Marc Röschlin, and Srdjan Capkun. LTrack: Stealthy tracking of mobile phones in LTE. In31st USENIX Security Symposium (USENIX Security 22), pages 1291–1306, Boston, MA, August 2022. USENIX Association
2022
-
[39]
Tesla warns of theft risk through relay attacks, shares ‘tips’ to help prevent
Fred Lambert. Tesla warns of theft risk through relay attacks, shares ‘tips’ to help prevent. https://electr ek.co/2022/04/18/tesla-warns-theft-risk-t hrough-relay-attacks-shares-tips-prevent/ , 2022
2022
-
[40]
This is your president speaking: Spoofing alerts in 4g lte networks
Gyuhong Lee, Jihoon Lee, Jinsung Lee, Youngbin Im, Max Hollingsworth, Eric Wustrow, Dirk Grunwald, and Sangtae Ha. This is your president speaking: Spoofing alerts in 4g lte networks. MobiSys ’19, page 404–416, New York, NY , USA, 2019. Association for Computing Machinery
2019
-
[41]
SMS of Death: From Analyzing to Attacking Mobile Phones on a Large Scale
Collin Mulliner, Nico Golde, and Jean-Pierre Seifert. SMS of Death: From Analyzing to Attacking Mobile Phones on a Large Scale. InProceedings of the 20th USENIX Security Symposium, 2011
2011
-
[42]
Injecting SMS Mes- sages into Smart Phones for Security Analysis
Collin Mulliner and Charlie Miller. Injecting SMS Mes- sages into Smart Phones for Security Analysis. InPro- ceedings of the 3rd USENIX Workshop on Offensive Technologies (WOOT), 2009
2009
-
[43]
5g steering the future of connected cars
Nokia. 5g steering the future of connected cars. https: //www.nokia.com/about-us/newsroom/articles/ 5g-steering-the-future-of-connected-cars/ ,
-
[44]
Enabling physical localization of unco- operative cellular devices
Taekkyung Oh, Sangwook Bae, Junho Ahn, Yonghwa Lee, Hoang Tuan, Min Kang, Nils Ole Tippenhauer, and Yongdae Kim. Enabling physical localization of unco- operative cellular devices. InACM MobiCom ’24: Pro- ceedings of the 30th Annual International Conference on Mobile Computing...
2024
-
[45]
Osmocom Project.pySim: Programmable SIM Card Tool, 2025
2025
-
[46]
Imsi catchers in the wild: A real world 4g/5g assessment.Computer Networks, 194:108137, 2021
Ivan Palamà, Francesco Gringoli, Giuseppe Bianchi, and Nicola Blefari-Melazzi. Imsi catchers in the wild: A real world 4g/5g assessment.Computer Networks, 194:108137, 2021
2021
-
[47]
Anatomy of commercial imsi catch- ers and detectors.Proceedings of the 18th ACM Work- shop on Privacy in the Electronic Society, 2019
Shinjo Park, Altaf Shaik, Ravishankar Borgaonkar, and Jean-Pierre Seifert. Anatomy of commercial imsi catch- ers and detectors.Proceedings of the 18th ACM Work- shop on Privacy in the Electronic Society, 2019
2019
-
[48]
5G/4G LTE Automotive- Grade Connectivity Module
Quectel Wireless Solutions.Quectel AG525R-GL Mo- dem Connectivity Card, 2025. 5G/4G LTE Automotive- Grade Connectivity Module
2025
-
[49]
Tesla’s reliability concerns: Steering and sus- pension issues
Reuters. Tesla’s reliability concerns: Steering and sus- pension issues. https://www.reuters.com/inve stigates/special-report/tesla-musk-steerin g-suspension/, 2025
2025
-
[50]
How to hack a tesla model s
Marc Rogers and Kevin Mahaffey. How to hack a tesla model s. InDEF CON 23, 2015
2015
-
[51]
Breaking lte on layer two
David Rupprecht, Katharina Kohls, Thorsten Holz, and Christina Pöpper. Breaking lte on layer two. In2019 IEEE Symposium on Security and Privacy (SP), pages 1121–1136, 2019
2019
-
[52]
Imp4gt: Impersonation attacks in 4g networks.Proceedings 2020 Network and Distributed System Security Symposium, 2020
David Rupprecht, Katharina Siobhan Kohls, Thorsten Holz, and Christina Pöpper. Imp4gt: Impersonation attacks in 4g networks.Proceedings 2020 Network and Distributed System Security Symposium, 2020
2020
-
[53]
Asokan, Valt- teri Niemi, and Jean-Pierre Seifert
Altaf Shaik, Ravishankar Borgaonkar, N. Asokan, Valt- teri Niemi, and Jean-Pierre Seifert. Practical attacks against privacy and availability in 4g/lte mobile commu- nication systems.CoRR, abs/1510.07563, 2015
2015 arXiv
-
[54]
On the impact of rogue base stations in 4g/lte self organizing networks
Altaf Shaik, Ravishankar Borgaonkar, Shinjo Park, and Jean-Pierre Seifert. On the impact of rogue base stations in 4g/lte self organizing networks. InProceedings of the 11th ACM Conference on Security & Privacy in Wireless and Mobile Networks, WiSec ’18, page 75–86, New York, ...
2018
-
[55]
New vulnerabilities in 4g and 5g cellular access network protocols: exposing device ca- pabilities
Altaf Shaik, Ravishankar Borgaonkar, Shinjo Park, and Jean-Pierre Seifert. New vulnerabilities in 4g and 5g cellular access network protocols: exposing device ca- pabilities. InProceedings of the 12th Conference on Security and Privacy in Wireless and Mobile Networks, WiSec ’1...
2019
-
[56]
SRS (Software Radio Systems).srsRAN: Open-source 4G and 5G Software Radio Suite, 2025
2025
-
[57]
Under pressure: Exploring a zero-click rce vulnerability in tesla’s tpms
Synacktiv. Under pressure: Exploring a zero-click rce vulnerability in tesla’s tpms. InPwn2Own Vancouver 2024, 2024
2024
-
[58]
Programmable SIM Card for LTE and 5G Testing
Sysmocom GmbH.sysmoISIM-SJA5 SIM Card, 2025. Programmable SIM Card for LTE and 5G Testing
2025
-
[59]
Tesla.Cybertruck 2024+ Service Manual, 2024
Inc. Tesla.Cybertruck 2024+ Service Manual, 2024
2024
-
[60]
Tesla.Model 3 2024+ Service Manual, 2024
Inc. Tesla.Model 3 2024+ Service Manual, 2024
2024
-
[61]
Proprietary diagnostic software used for Tesla vehicle maintenance and configuration
Tesla, Inc.Tesla Toolbox Software, 2025. Proprietary diagnostic software used for Tesla vehicle maintenance and configuration
2025
-
[62]
Criminals using fake mobile towers in australia
The Australian. Criminals using fake mobile towers in australia. https://www.theaustralian.com.au /business/technology/criminals-hacking-int o-phones-using-dirtboxes-in-backs-of-car s-to-create-fake-mobile-towers/news-story /0bf900d16d8e32614ff1ebb75adc2587, 2024
2024
-
[63]
Spy ring plotted to obtain details from phones of ukrainians at u.s
The Guardian. Spy ring plotted to obtain details from phones of ukrainians at u.s. air base in germany. https: //www.theguardian.com/uk-news/2024/dec/03/ spy-ring-plotted-to-obtain-details-from-p hones-of-ukrainians-at-us-air-base-in-ger many-uk-court-hears, 2024
2024
-
[64]
Android 14 adds new security features to protect against cellular threats
The Hacker News. Android 14 adds new security features to protect against cellular threats. https: //thehackernews.com/2024/10/android-14-a dds-new-security-features.html, 2024
2024
-
[65]
The iPerf Project.iPerf3: Network Bandwidth Measure- ment Tool, 2025
2025
-
[66]
The Tcpdump Group.tcpdump: Packet Analyzer, 2025
2025
-
[67]
TP-Link.AC1750 Wireless Dual Band Gigabit Router, 2025
2025
-
[68]
Detecting imsi-catchers by characterizing iden- tity exposing messages in cellular traffic
Tyler Tucker, Nathaniel Bennett, Martin Kotuliak, Si- mon Erni, Srdjan Capkun, Kevin Butler, and Patrick Traynor. Detecting imsi-catchers by characterizing iden- tity exposing messages in cellular traffic. InNetwork and Distributed System Security (NDSS) Symposium 2025, page 1...
2025
-
[69]
Car infotainment hacking methodology and attack surface scenarios
Jay Turla. Car infotainment hacking methodology and attack surface scenarios. InDEF CON 26 Packet Hack- ing Village, 2018
2018
-
[70]
Un regulation no
United Nations Economic Commission for Europe (UN- ECE). Un regulation no. 155: Cybersecurity and cyber- security management system. Technical report, UNECE World Forum for Harmonization of Vehicle Regulations (WP.29), 2021
2021
-
[71]
Un regulation no
United Nations Economic Commission for Europe (UN- ECE). Un regulation no. 156: Software update and software update management system. Technical report, UNECE World Forum for Harmonization of Vehicle Regulations (WP.29), 2021
2021
-
[72]
Free-fall: Hacking tesla from wireless to can bus
Ralf-Philipp Weinmann. Free-fall: Hacking tesla from wireless to can bus. InBlack Hat USA 2020, 2020
2020
-
[73]
Thwarting smartphone sms attacks at the radio interface layer
Haohuang Wen, Phillip Porras, Vinod Yegneswaran, and Zhiqiang Lin. Thwarting smartphone sms attacks at the radio interface layer. InProceedings of the 30th Annual Network and Distributed System Security Symposium (NDSS’23), San Diego, CA, February 2023
2023
-
[74]
Unauthorized deployment of cell-site simulators at 2024 dnc
Wired. Unauthorized deployment of cell-site simulators at 2024 dnc. https://www.wired.com/story/2024 -dnc-cell-site-simulator-phone-surveillanc e, 2025
2024
-
[75]
Wireshark Foundation.Wireshark: Network Protocol Analyzer, 2025
2025
-
[76]
My other car is your car: Compro- mising the tesla model x keyless entry system
Lennert Wouters. My other car is your car: Compro- mising the tesla model x keyless entry system. InPro- ceedings of the 2020 IEEE Symposium on Security and Privacy (SP), 2020
2020
-
[77]
Access your tesla without your aware- ness: Compromising keyless entry system of model 3
Lennert Wouters. Access your tesla without your aware- ness: Compromising keyless entry system of model 3. In Proceedings of the 2021 IEEE Symposium on Security and Privacy (SP), 2021
2021
-
[78]
XDA Developers.Android Dialer Service, 2025
2025
-
[79]
Hiding in plain signal: Physical signal overshadowing attack on LTE
Hojoon Yang, Sangwook Bae, Mincheol Son, Hongil Kim, Song Min Kim, and Yongdae Kim. Hiding in plain signal: Physical signal overshadowing attack on LTE. In28th USENIX Security Symposium (USENIX Secu- rity 19), pages 55–72, Santa Clara, CA, August 2019. USENIX Association
2019
-
[80]
Lte phone number catcher: A practical attack against mobile privacy
Chuan Yu, Shuhui Chen, Zhiping Cai, and Jesús Díaz- Verdejo. Lte phone number catcher: A practical attack against mobile privacy. 2019, January 2019. A. LTE Architecture Long-Term Evolution (LTE) [2] is designed around a simpli- fied, packet-centric framework known as the Evol...
2019
-
[81]
Removed the headliner to access the SIM slot
-
[82]
Since the TCU remains powered even after the vehicle is off, the 12V battery under the rear seat was disconnected to ensure a complete power cycle before inserting the new SIM
Shut down the Tesla and disconnect the 12V battery. Since the TCU remains powered even after the vehicle is off, the 12V battery under the rear seat was disconnected to ensure a complete power cycle before inserting the new SIM
-
[83]
Inserted the SIM card securely into the slot
-
[84]
This step ensured that all vehicle sub- systems, including the TCU, received a proper reset after the SIM swap
Reconnected the 12V battery and waited for the power relay to “click". This step ensured that all vehicle sub- systems, including the TCU, received a proper reset after the SIM swap
-
[85]
Hard Reboots
Turned on the Tesla and allowed the system to initial- ize. The vehicle’s network stack was then given time to attempt attachment. Figure 10: SIM Activation in the Tesla Toolbox. Figure 11: Successful physical SIM card activation. “Hard Reboots" (Full Power Cycle), which mean ...
Reviewed August 4, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.