keycap_puller If in possession of it but not your PIN/Password, other than making a call there isn't much they can do, even if they made the call and activated the radio, they would have to have aforementioned exploit chain to then use it somehow to access the OS and your data. The radio in and of itself regardless to vulnerabilities to itself, isn't a direct vector to the OS.
If they have your PIN/Password then the radio is irrelevant anyway and if it isn't in BFU state having a low auto reboot timer will help you get further peace of mind.