Vulnerabilities in CPDLC Communications: Fake Messages and Radio-Induced Disconnections

Learn about CPDLC vulnerabilities in ATN-B1 systems, including fake messages and disconnections from CISA advisory ICSA-26-219-01. CVE details included.

Vulnerabilities in CPDLC Communications: Fake Messages and Radio-Induced Disconnections
Vulnerabilities

Illustrative image generated with AI

The ATN-B1 system exposes communications to remote interference

The CISA/CSAF advisory icsa-26-219-01, published on August 7, 2026, concerns CPDLC over ATN-B1, the system used to exchange data between aircraft and air traffic control infrastructure.

The link relies on radio-frequency communications that are unencrypted and unauthenticated. An attacker can therefore operate remotely over the radio channel without necessarily compromising an onboard system or ground network directly.

The affected scope includes:

  • Product: CPDLC over ATN-B1 Vulnerabilities;
  • standard: Advisory Circular 90-117 Data Link Communications;
  • version: ATN-B1 CPDLC: vers:all/*;
  • status: known_affected;
  • sector: transportation systems;
  • deployment: worldwide.

The vendor has not been identified, and no fixed or unaffected versions have been disclosed.

Five CVEs affect authentication and session continuity

CVE-2025-71409 concerns the lack of authentication for Very High Frequency Data Link messages. Malicious ground stations could inject CPDLC messages, creating unexpected or deceptive clearances and increasing the risk of pilot confusion.

The flaw is classified as CWE-306, with HIGH severity and a CVSS 3.1 score of 7.1. The CVSS 4.0 score is also 7.1.

CVE-2025-71410 and CVE-2025-71411 affect service availability. Unnumbered Disconnect (U DISC) messages and malformed Aviation Very High Frequency Link Control frames can terminate CPDLC sessions. Another type of broadcast control frame can disconnect multiple aircraft simultaneously.

Both vulnerabilities are rated MEDIUM, with CVSS 3.1 scores of 5.3 and CVSS 4.0 scores of 6.0. They are associated with CWE-770, which covers resource allocation without limits or throttling mechanisms.

The same set also includes CVE-2025-71412 and CVE-2025-71413. No technical descriptions, CWE classifications, or specific CVSS metrics are currently available for these identifiers.

The effects impact pilots and air traffic controllers

The attacks described can compromise communication integrity, disrupt CPDLC functions, and force a return to voice communications. This may increase controller workload and delay operational instructions.

The impact is not described as an unsafe airworthiness condition. However, fake messages, terminated sessions, and delayed clearances can reduce operational safety margins, particularly by diminishing situational awareness.

The summary table assigns the vulnerabilities an overall CVSS v3 severity of 7.1. Confidentiality is not listed among the primary impacts.

No patches or workarounds have been publicly released

No patches, updates, workarounds, or other specific mitigations have been identified. As a result, all deployments conforming to ATN-B1 CPDLC: vers:all/* fall within the known scope of exposure.

Operators should consult CPDLC system and ATC infrastructure owners to determine whether operational guidance is available. In particular, they should monitor for anomalous session establishment or termination attempts, unexpected CPDLC messages, and simultaneous disconnections affecting multiple aircraft.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →