Remote message injection and session termination vulnerabilities threaten ATN-B1 CPDLC aviation systems
High-severity vulnerabilities in the ATN-B1 CPDLC system allow remote attackers to inject false messages or terminate active sessions via radio frequency. These flaws can cause pilot confusion, unexpected clearances, and increased air traffic controller workloads. Defenders should prepare for potential shifts from digital data links back to manual voice communication during an incident.
Summary
The ATN-B1 Controller Pilot Data Link Communications (CPDLC) system contains several vulnerabilities that permit remote message injection and session disruption. Because these attacks can be executed over radio frequency, a rogue ground station could interfere with aviation communications without direct network access. The flaws impact the integrity of clearances and the availability of digital communication functions.
Technical details
The vulnerabilities center on the lack of authentication for Very High Frequency (VHF) Data Link messages and the handling of specific control frames.
One primary risk involves the injection of false data. An attacker can transmit unauthenticated messages to provide unexpected or misleading clearances, which may lead to improper response actions by flight crews or ground operations. This includes the potential for injecting false emergency or status messages.
Other vulnerabilities target the stability of the communication session. Attackers can use specific frames to disrupt service:
- Unnumbered Disconnect (U DISC) and malformed control frames: These can terminate active sessions, forcing a reversion to voice communication.
- Broadcast control frames: These allow for the simultaneous disconnection of multiple aircraft, which may result in delayed clearances and increased workload for air traffic controllers.
- Out-of-sequence frames: Malformed frames at the X.25 layers can cause repeated resets, reducing situational awareness during flight operations.
Affected products and fixed versions
| CVE ID | Severity | Impact | Description |
|---|---|---|---|
| CVE-2025-71409 | High (7.1) | Integrity/Availability | Injection of unexpected or misleading clearances via rogue ground stations. |
| CVE-2025-71412 | High (7.1) | Integrity/Availability | Injection of false emergency or status messages. |
| CVE-2025-71410 | Medium (6.0) | Availability | Session termination via U DISC or malformed control frames. |
| CVE-2025-71411 | Medium (6.0) | Availability | Multiple aircraft disconnection via broadcast control frames. |
| CVE-2025-71413 | Medium (6.0) | Availability | Repeated session resets due to malformed X.25 layer frames. |
Why this matters for defenders
The attack vector is physical and remote, relying on radio frequency rather than traditional IP networking. This means a rogue ground station can disrupt communications without needing access to an internal aviation network.
For air traffic control and flight operations, the primary consequence of these vulnerabilities is the sudden loss of digital data link capabilities. When CPDLC functions fail or are terminated by malformed frames, personnel must revert to voice communication. This transition increases controller workload and can lead to operational confusion during critical phases of flight.
