The 2022 Pwnie Nominee For Most Innovative Research

FirmWire

Researchers: @Digital_Cold, @nSinusR & @domenuk

FirmWire is the first scalable and fully open source baseband emulation framework.
While started as academic research and just scratching the (attack) surface, it had direct practical implications and allowed the discovery for multiple critical vulnerabilities in the Samsung Shannon baseband, including arbitrary remote code execution over the air (c.f. https://firmwire.github.io/docs/trophy_wall.html).
Besides this, the framework was used to dynamically test more than 200 baseband firmwares across 9 device models, providing insights about vendor patch cycles and patch propagation.