highOther

CPDLC over ATN-B1 Protocol Vulnerabilities

First seen Aug 8, 2026 · Updated Aug 8, 2026 · CVSS 7.1

aviationicsotprotocol-vulnerabilitydosmessage-injectionradio-frequencycritical-infrastructure

Five vulnerabilities in the Controller-Pilot Data Link Communications (CPDLC) protocol over ATN-B1, used for aircraft-air traffic control text communications, allow unauthenticated message injection, denial-of-service, and forced session resets via unauthenticated clear-text radio frequency links. While not creating an unsafe aircraft condition directly, exploitation can degrade operational safety margins by increasing controller/pilot workload, delaying safety-critical instructions, and reducing situational awareness. No public exploitation has been observed, and attack complexity is high, requiring lab-like conditions.

Technical Analysis

The vulnerabilities stem from CPDLC's lack of authentication (CWE-306) and improper resource throttling/exception handling (CWE-770, CWE-754) at the Aviation VHF Link Control and X.25 layers. CVE-2025-71409 (CVSS 7.1) allows rogue ground stations to inject spoofed clearances due to missing authentication on VHF Data Link messages. CVE-2025-71410 and CVE-2025-71413 (CVSS 5.3) enable session termination via malformed/out-of-sequence frames or Unnumbered Disconnect commands, forcing reversion to voice communications. CVE-2025-71411 (CVSS 5.3) permits broadcast frames to disconnect multiple aircraft simultaneously, and CVE-2025-71412 (CVSS 7.1) allows injection of false emergency/status messages causing improper response actions. These are legacy aviation OT protocol flaws affecting physical-world air traffic systems rather than IT/AI infrastructure, and there is no plausible direct impact to AI agent, LLM, or RAG pipeline systems from this advisory.

Affected Systems

ATN-B1 CPDLC implementations (all versions) used in Controller-Pilot Data Link Communications systems compliant with Advisory Circular 90-117 Data Link Communications, deployed worldwide in aviation air traffic control and avionics systems.

Indicators of Compromise

  • No file-based or network IOCs applicable; this is a protocol-level design vulnerability rather than a malware/exploit artifact.

Remediation Steps

  1. 1

    No vendor patch available

    There is currently no mitigation or patch available for CVE-2025-71409 through CVE-2025-71413; monitor CISA advisory icsa-26-219-01 for updates.

  2. 2

    Report suspicious activity

    Organizations observing suspected malicious CPDLC activity should follow internal incident response procedures and report findings to CISA for tracking and correlation.

  3. 3

    Maintain voice communication fallback

    Ensure air traffic control and flight crew procedures maintain readiness to revert to voice communications in the event of CPDLC session disruption or suspected message injection.

  4. 4

    Monitor for anomalous CPDLC sessions

    Implement monitoring for unexpected session resets, malformed frames, or unusual disconnect patterns that may indicate exploitation attempts, given the high attack complexity limits likely to lab/research conditions currently.

CVE / Advisory IDs

CVE-2025-71409CVE-2025-71410CVE-2025-71411CVE-2025-71412CVE-2025-71413

Industries Most Exposed

Transportation SystemsAviation

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.