A quick packet captures on the cellular interface of the MX and the WAN interface of the hub should reveal whether the devices are sending UDP packets to build the auto-VPN. A successful connection should show bidirectional or two-way UDP traffic between the peers. If you see unidirectional traffic only on either or both peers, then the traffic is being dropped or filtered upstream. Service providers use CGNAT (carrier-grade NAT) in cellular deployments which is known to cause issues with auto-VPN connection due to how this is implemented.
Please hit kudos if you found this post helpful and/or click "accept as solution" if this solved your problem.