Earlier quoted context omitted.
These open source / DIY mobile devices rely on an IC to perform the telephony side of things. In this example, a SIM800C made by SIMCom which could require additional "features" to pass certifications. How would you ensure there is no existing backdoor in the chip's firmware?
> How would you ensure there is no existing backdoor in the chip's firmware? What is the worst thing that backdoor could do?
Basically, taking complete control of the modem and potentially using that as a launch point for a more detailed attack.
Besides that, in the US at least, your phone's cell modem does have a backdoor. Every single one of them, no exceptions. Your telco can remotely update your modem's firmware and there is absolutely nothing you can do to stop it. Telcos are allowed/required to have total control of the firmware of any modem attached to their network. Source code is never, ever available. All cell modems are a total black box.
This also applies to terrestrial internet connections. Your cable modem or DSL has a firmware blob provided by your telco, no matter who you bought the modem from.