Open
Description
Hello, thanks for the repo first of all.
I'm trying the V8 "Invalid RRC Setup spCellConfig" vs a OnePlus Nord CE 2 5G with a M_V3_P10 firmware version described in your paper. I've few question:
- in the monitor.1.txt i can't find the "[ASSERT] file:mcu/l1/mml1/mml1_endc/src/mml1_endc_db_hdlr.c line:524 p1:0x91920c70"
- in the pcapng file I can't visualize RRC and MAC shown in your description, but something different. I'm missing something probably...
- I've understood that this kind of test (like others) is triggered when phone is toggled in airplane mode on/off and forced to reattach to the network, is it possible to trigger the phone to connect to rogue BS in a different way? For example like higher signal of rouge BS?
Thanks for the info
BR
Desi
Metadata
Metadata
Assignees
Labels
No labels