The setup
A private network on a bench, a commercial modem, and a capture point between them. Nothing exotic: the point of the exercise is to see what the device can address once it has attached, not to build an unusual lab.
Reaching the core
With filtering absent or misapplied, traffic from the subscriber side reaches services that were never meant to be addressable from a handset. The interesting part is not that it happens, but how ordinary the packets look while it does.
What operators do about it
The mechanisms exist and most operators deploy something. What differs is where the boundary sits, which interfaces it covers, and whether it survives a configuration change six months later.
Radio-side exposure is a configuration problem wearing a protocol costume. It rewards testing on the network you actually run, not the one in the architecture diagram.
Testing it yourself
The same lab fits on a desk. Bring a transceiver, an open-source core, and a device you are allowed to attach, then work outwards from what answers.
Conclusion
Mobile operators generally know this attack vector and apply suitable mechanisms to avoid risk from the subscriber context. Those mechanisms differ from one operator to another, and their effectiveness varies. Core network testing is a scoped engagement, not a slide deck: if you want this run against your own network, get in touch.
Core network testing is a scoped engagement, not a slide deck.