Critical

CPDLC over ATN-B1 Vulnerabilities

All CISA Advisories

Overview

Recent research has identified several vulnerabilities in the Controller-Pilot Data Link Communications (CPDLC) system that operates over the Aeronautical Telecommunications Network (ATN-B1). These vulnerabilities stem from the use of legacy, unauthenticated radio frequency links, which could allow attackers to inject unauthorized messages, disrupt communications, and reset sessions. Although these issues do not directly compromise aircraft safety, they could create confusion and increase the workload for pilots and air traffic controllers, potentially impacting operational safety. The vulnerabilities affect all versions of CPDLC over ATN-B1, with several specific CVEs (CVE-2025-71409 to CVE-2025-71413) documented. Currently, there are no available mitigations or patches for these vulnerabilities, and while they can be exploited in laboratory settings, there have been no reports of active exploitation in the wild.

Key Takeaways

  • Affected Systems: Affected products include all versions of CPDLC over ATN-B1. Specific vulnerabilities include CVE-2025-71409 (lack of authentication), CVE-2025-71410 (session termination), CVE-2025-71411 (disconnecting multiple aircraft), CVE-2025-71412 (injection of false messages), and CVE-2025-71413 (not specified).
  • Action Required: Currently, there are no mitigations available for the vulnerabilities.
  • Timeline: Newly disclosed

Original Article Summary

View CSAF Summary ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links. Research demonstrates that these characteristics allow unauthorized message injection, denial-of-service conditions, and forced session resets. These vulnerabilities do not constitute an unsafe aircraft condition but can degrade operational safety margins by increasing workload, delaying safety-critical instructions, and reducing situational awareness. The following versions of CPDLC over ATN-B1 Vulnerabilities are affected: ATN-B1 CPDLC vers:all/* (CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413) CVSS Standard Equipment Vulnerabilities v3 7.1 Advisory Circular 90-117 Data Link Communications CPDLC over ATN-B1 Vulnerabilities Missing Authentication for Critical Function, Allocation of Resources Without Limits or Throttling, Improper Check for Unusual or Exceptional Conditions Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Global Vulnerabilities Expand All + CVE-2025-71409 Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. This type of attack can be carried out remotely over radio frequency. View CVE Details Affected Products CPDLC over ATN-B1 Vulnerabilities Standard: Advisory Circular 90-117 Data Link Communications Product Version: Advisory Circular 90-117 Data Link Communications ATN-B1 CPDLC: vers:all/* Product Status: known_affected Remediations None available Currently, there is no mitigation available for CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413. Mitigation These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting. Mitigation Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Mitigation No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities have a high attack complexity. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.1 HIGH CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L 4.0 7.1 HIGH CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L CVE-2025-71410 Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC functions requiring a reversion to voice communication and increased controller workload. This type of attack can be carried out remotely over radio frequency. View CVE Details Affected Products CPDLC over ATN-B1 Vulnerabilities Standard: Advisory Circular 90-117 Data Link Communications Product Version: Advisory Circular 90-117 Data Link Communications ATN-B1 CPDLC: vers:all/* Product Status: known_affected Remediations None available Currently, there is no mitigation available for CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413. Mitigation These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting. Mitigation Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Mitigation No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities have a high attack complexity. Relevant CWE: CWE-770 Allocation of Resources Without Limits or Throttling Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H 4.0 6 MEDIUM CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2025-71411 Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency. View CVE Details Affected Products CPDLC over ATN-B1 Vulnerabilities Standard: Advisory Circular 90-117 Data Link Communications Product Version: Advisory Circular 90-117 Data Link Communications ATN-B1 CPDLC: vers:all/* Product Status: known_affected Remediations None available Currently, there is no mitigation available for CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413. Mitigation These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting. Mitigation Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Mitigation No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities have a high attack complexity. Relevant CWE: CWE-770 Allocation of Resources Without Limits or Throttling Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H 4.0 6 MEDIUM CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2025-71412 Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic controllers, and ground operations. This type of attack can be carried out remotely over radio frequency. View CVE Details Affected Products CPDLC over ATN-B1 Vulnerabilities Standard: Advisory Circular 90-117 Data Link Communications Product Version: Advisory Circular 90-117 Data Link Communications ATN-B1 CPDLC: vers:all/* Product Status: known_affected Remediations None available Currently, there is no mitigation available for CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413. Mitigation These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting. Mitigation Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Mitigation No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities have a high attack complexity. Relevant CWE: CWE-754 Improper Check for Unusual or Exceptional Conditions Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.1 HIGH CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L 4.0 7.1 HIGH CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L CVE-2025-71413 Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets which may result in increased workload and reduced situational awareness. This type of attack can be carried out remotely over radio frequency. View CVE Details Affected Products CPDLC over ATN-B1 Vulnerabilities Standard: Advisory Circular 90-117 Data Link Communications Product Version: Advisory Circular 90-117 Data Link Communications ATN-B1 CPDLC: vers:all/* Product Status: known_affected Remediations None available Currently, there is no mitigation available for CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413. Mitigation These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting. Mitigation Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Mitigation No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities have a high attack complexity. Relevant CWE: CWE-754 Improper Check for Unusual or Exceptional Conditions Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H 4.0 6 MEDIUM CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Acknowledgments Martin Strohmeier of Armasuisse reported these vulnerabilities to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Revision History Initial Release Date: 2026-08-07 Date Revision Summary 2026-08-07 1 Initial Publication Legal Notice and Terms of Use

Impact

Affected products include all versions of CPDLC over ATN-B1. Specific vulnerabilities include CVE-2025-71409 (lack of authentication), CVE-2025-71410 (session termination), CVE-2025-71411 (disconnecting multiple aircraft), CVE-2025-71412 (injection of false messages), and CVE-2025-71413 (not specified).

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Newly disclosed

Remediation

Currently, there are no mitigations available for the vulnerabilities. Organizations are advised to monitor for suspicious activity and report findings to CISA.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Critical.

Related Coverage

ShinyHunters claims social engineering attack against ReliaQuest

SCM feed for Latest

A group known as ShinyHunters claims to have executed a social engineering attack against ReliaQuest. The attackers targeted employees by calling them and attempting to deceive them into visiting a fraudulent single sign-on (SSO) page. This fake page was hosted on a lookalike domain, reliaquest[.]claims, designed to mimic the legitimate ReliaQuest site. Such tactics can lead to credential theft and unauthorized access to sensitive company data. This incident raises concerns about the effectiveness of security training and awareness among employees, as social engineering remains a prevalent threat in cybersecurity.

Aug 24, 2026

WordPress plugin vulnerabilities allow admin account takeover

SCM feed for Latest

Researchers have identified two vulnerabilities in WordPress plugins, tracked as CVE-2026-61979 and CVE-2026-15981, that can be exploited together to bypass authentication and potentially take over admin accounts. This poses a significant risk to users of affected plugins, as attackers could gain unauthorized access to sensitive areas of WordPress sites. The vulnerabilities are particularly concerning for website administrators who may not be aware of these security flaws. It's crucial for users to check if their plugins are affected and take appropriate action to secure their sites, especially since the potential for exploitation exists. Prompt updates and vigilance are key to maintaining site security in light of these findings.

Aug 24, 2026

Developer alleges Alibaba uses audio fingerprinting for web tracking

SCM feed for Latest

Matt Callaghan, a software engineer, has raised concerns that Alibaba's website may be using audio fingerprinting techniques for tracking users. He found that the site employs obfuscated audio scripts that create a waveform and analyze its output, which could allow the company to monitor user behavior in a way that bypasses traditional tracking methods. This discovery raises significant privacy issues, as it suggests that users may be unwittingly tracked through audio signals emitted from their devices. The implications are serious, especially for individuals who value their privacy online. The use of such techniques could lead to increased scrutiny from regulators and may prompt users to reconsider their interactions with the site.

Aug 24, 2026

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

darkreading

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent three-day deadline for agencies to address a serious vulnerability in Zimbra, identified as CVE-2026-73570. This flaw enables attackers to take complete control over a user's communications, posing a significant risk to organizations using this software. The vulnerability could lead to unauthorized access to sensitive information and disrupt business operations. As Zimbra is widely used for email and collaboration, the implications of this vulnerability are considerable, affecting both public and private sector entities. Agencies are urged to act quickly to implement the necessary patches to mitigate this risk.

Aug 24, 2026

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

BleepingComputer

A vulnerability in Calix GS7 XGS residential routers, specifically the GS5239XG model, has been discovered, allowing attackers to bypass Network Address Translation (NAT) settings. This flaw enables remote, unauthenticated users to set up port-forwarding rules, which could expose internal devices on a user's local network to the public internet. The issue affects multiple broadband providers in the U.S. and poses significant risks as it could lead to unauthorized access to sensitive devices within homes. As of now, the vulnerability remains unpatched, leaving users at risk of potential exploitation unless action is taken to secure their networks. It's crucial for users of these routers to remain vigilant and consider disabling remote management features until a fix is provided.

Aug 24, 2026

CISA adds Zimbra Collaboration Suite bug to exploited vulnerabilities list

SCM feed for Latest

The Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability in the Zimbra Collaboration Suite to its list of actively exploited vulnerabilities. This marks the fifth time this year that Zimbra has appeared on the Known Exploited Vulnerabilities (KEV) list, indicating a troubling trend for users of this software. The vulnerability could allow attackers to gain unauthorized access to sensitive information, which poses a significant risk for organizations that rely on Zimbra for communication and collaboration. Users are advised to take immediate action to secure their systems, as the ongoing exploitation of this flaw highlights the importance of timely software updates and patches. Organizations using Zimbra should ensure they are running the latest versions and monitor for any signs of compromise.

Aug 24, 2026