VORANT. Threat Intelligence Sign in Get the full feed

Unauthenticated CPDLC flaws let rogues inject clearances

routine vulnerability transportation

Five unauthenticated-protocol flaws in ATN-B1 CPDLC air traffic messaging allow rogue radio stations to inject or disrupt pilot/controller communications, with no fix available.

CISA published an ICS advisory detailing five vulnerabilities in the Controller-Pilot Data Link Communications (CPDLC) protocol as implemented over ATN-B1, the datalink used for air traffic control clearances worldwide. The root cause is architectural: CPDLC relies on clear-text, unauthenticated VHF radio links, which permits an attacker with radio equipment to inject spoofed clearance or emergency messages, forcibly terminate sessions (forcing reversion to voice comms), and disconnect multiple aircraft simultaneously via broadcast control frames. None of the flaws create an unsafe aircraft condition on their own, but they can degrade operational safety margins by increasing controller/pilot workload, delaying safety-critical instructions, and reducing situational awareness.

The five CVEs (CVE-2025-71409 through CVE-2025-71413) cover missing authentication for VHF data link messages, malformed/unnumbered disconnect frames terminating sessions, broadcast frames causing mass disconnects, injection of false emergency/status messages, and malformed X.25-layer frames causing repeated resets. All require radio-frequency proximity and are rated high attack complexity; CISA states the issues have been demonstrated in a lab environment by researcher Martin Strohmeier (Armasuisse) and that no public exploitation has been observed in the wild. No patches or mitigations currently exist, and organizations are advised only to report suspicious activity through established channels.

Given the lack of active exploitation, the lab-only demonstration, high attack complexity, and the advisory's own assessment that these do not create an unsafe aircraft condition, this is a notable but not urgent protocol-design disclosure affecting global aviation transportation infrastructure. It underscores a long-standing legacy weakness in CPDLC/ATN-B1 that will require industry-wide protocol authentication improvements rather than a simple patch.

Mentioned in this report

Vulnerabilities CVE-2025-71409CVE-2025-71410CVE-2025-71411CVE-2025-71412CVE-2025-71413

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-219-01

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free