They can already do this via singray and other cell tower acquisitions.
You don't own the baseband firmware, therefore do not trust the device.
The same is true of your desktop and likely router gear, but many of those at least require brief physical access to enable (however there's also in transit or baked in at the factory).
If you want a truly secure device demand fully open.