Hack.lu 2026

LTECruiser: An Extremely low cost LTE Experimentation Framework

LTECruiser turns a 14€ LTE USB dongle into a firmware experimentation platform for cellular protocols and baseband security research. In this talk, we show how the ML307A, an inexpensive USB LTE Cat. 1 modem sold for IoT use by ASR Microelectronics, can be repurposed into a practical research platform through public firmware artifacts, an exposed diagnostic port, existing vendor tools and AT command interfaces.
Starting from the ELF firmware with debugging data available on GitHub, we document the internal code structure of the LTE modem by analyzing its boot phase and the related paths for handling received/transmitted data from the layer 1 co-processor, we then build a cross-platform userspace framework for Linux and Windows to communicate with the modem through AT commands, dump memory, patch live firmware and inject custom ARM32 code at runtime. We then use these primitives to explore the baseband code and demonstrate how this ultra low cost device can be pushed far beyond its intended role, showing the implementation of a LTE sniffer through firmware patching in a controlled environment. The result is an extremely cheap, widely available and practical platform for LTE security research based on commodity off-the-shelf (COTS) hardware.


LTE remains one of the most important telecommunications technologies, despite having been introduced in 2008.
Since then, a substantial body of research has examined the protocol’s security properties, analyzing security vulnerabilities inside the firmware and protocol attacks;
however, one major limitation has persisted: the lack of a truly low-cost platform for experimenting directly with the User Equipment hardware.
In this talk, for the first time, we present an extremely inexpensive USB LTE Cat 1 modem, available for $14 on Amazon, the underlying hardware employed is the ML307A chip: produced by ASR Microelectronics, widely used in various consumer and industrial IoT products.
Although it initially appears to be a simple low-cost and low-speed dongle, we show that it exposes a far richer research surface than expected.
In particular, its firmware is available on GitHub as an ELF file containing debug information, providing thus an unusual starting point for developing our research.
Building on this, we develop a custom userspace driver for both Linux and Windows which permits the direct interaction with the modem through AT commands.
We then examine the available tools provided by ASR, the hardware vendor, including utilities that allow firmware log extraction by polling data from the USB DIAG interface.
We then focus on the baseband firmware and survey the available AT command set, highlighting in particular the command AT*REGRW, which provides both read and write primitives into the dongle's memory.
Using these capabilities, we dump the running firmware and, by using as reference the ELF file,
construct a firmware-patching framework capable of injecting raw ARM32 instructions into RAM during live execution.
As a proof of concept, we demonstrate how this approach can be used to implement a simple LTE sniffer that forwards captured layer 2 packets to the host system.
We then finish the talk by exploring the high level protocols offered by the firmware: HTTP, FTP and TTS (text to speech), showing how it is possible to hook them for achieving a deeper level of interaction with the firmware.

Edoardo Mantovani

Independent (security) researcher with a specific focus on wireless firmware reverse engineering, kernel programming and software obfuscation. Previously spoken/accepted at Nullcon Berlin 2025, Hardwear.io USA 2026, SEC-T Sweden 2026, BlackAlps 2026, Hack.lu 2026 and CONFidence conference 2026.