Vulnerabilities in CPDLC Communications: Fake Messages and Radio-Induced Disconnections
Learn about CPDLC vulnerabilities in ATN-B1 systems, including fake messages and disconnections from CISA advisory ICSA-26-219-01. CVE details included.
Illustrative image generated with AI
The ATN-B1 system exposes communications to remote interference
The CISA/CSAF advisory icsa-26-219-01, published on August 7, 2026, concerns CPDLC over ATN-B1, the system used to exchange data between aircraft and air traffic control infrastructure.
The link relies on radio-frequency communications that are unencrypted and unauthenticated. An attacker can therefore operate remotely over the radio channel without necessarily compromising an onboard system or ground network directly.
The affected scope includes:
- Product: CPDLC over ATN-B1 Vulnerabilities;
- standard: Advisory Circular 90-117 Data Link Communications;
- version:
ATN-B1 CPDLC: vers:all/*; - status:
known_affected; - sector: transportation systems;
- deployment: worldwide.
The vendor has not been identified, and no fixed or unaffected versions have been disclosed.
Five CVEs affect authentication and session continuity
CVE-2025-71409 concerns the lack of authentication for Very High Frequency Data Link messages. Malicious ground stations could inject CPDLC messages, creating unexpected or deceptive clearances and increasing the risk of pilot confusion.
The flaw is classified as CWE-306, with HIGH severity and a CVSS 3.1 score of 7.1. The CVSS 4.0 score is also 7.1.
CVE-2025-71410 and CVE-2025-71411 affect service availability. Unnumbered Disconnect (U DISC) messages and malformed Aviation Very High Frequency Link Control frames can terminate CPDLC sessions. Another type of broadcast control frame can disconnect multiple aircraft simultaneously.
Both vulnerabilities are rated MEDIUM, with CVSS 3.1 scores of 5.3 and CVSS 4.0 scores of 6.0. They are associated with CWE-770, which covers resource allocation without limits or throttling mechanisms.
The same set also includes CVE-2025-71412 and CVE-2025-71413. No technical descriptions, CWE classifications, or specific CVSS metrics are currently available for these identifiers.
The effects impact pilots and air traffic controllers
The attacks described can compromise communication integrity, disrupt CPDLC functions, and force a return to voice communications. This may increase controller workload and delay operational instructions.
The impact is not described as an unsafe airworthiness condition. However, fake messages, terminated sessions, and delayed clearances can reduce operational safety margins, particularly by diminishing situational awareness.
The summary table assigns the vulnerabilities an overall CVSS v3 severity of 7.1. Confidentiality is not listed among the primary impacts.
No patches or workarounds have been publicly released
No patches, updates, workarounds, or other specific mitigations have been identified. As a result, all deployments conforming to ATN-B1 CPDLC: vers:all/* fall within the known scope of exposure.
Operators should consult CPDLC system and ATC infrastructure owners to determine whether operational guidance is available. In particular, they should monitor for anomalous session establishment or termination attempts, unexpected CPDLC messages, and simultaneous disconnections affecting multiple aircraft.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2025-71409High7.1Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. This type of attack can be carried out remotely over radio frequency.
- CVE-2025-71412High7.1Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic controllers, and ground operations. This type of attack can be carried out remotely over radio frequency.
- CVE-2025-71410Medium5.3Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC functions requiring a reversion to voice communication and increased controller workload. This type of attack can be carried out remotely over radio freque
- CVE-2025-71411Medium5.3Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.
- CVE-2025-71413Medium5.3Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets which may result in increased workload and reduced situational awareness. This type of attack can be carried out remotely over radio frequency.




