Sceawere
Vulnerability Detail
CVE-2025-71409UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
VHF Data Link Unauthenticated CPDLC Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 18h ago
- Vendor
- ATN-B1
- Product
- CPDLC
- Attack Type
- CWE-306
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. This type of attack can be carried out remotely over radio frequency.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-08-07T19:17:33.720Z",
"pubdate": "2026-08-07T19:17:33.720Z",
"executiveSummary": "This vulnerability involves a critical lack of authentication within Very High Frequency Data Link (VHDL) communications, specifically impacting Controller-Pilot Data Link Communications (CPDLC) messaging systems.\nThe absence of cryptographic message authentication allows unauthorized external entities operating rogue ground stations to transmit arbitrary, malicious, or spoofed data link messages directly to aircraft in flight.\nThe primary impact of this flaw is the potential injection of unexpected, misleading, or hazardous air traffic control clearances, resulting in severe pilot confusion, operational disruption, and potential safety-of-flight hazards.\nAffected systems include avionics and communication components that process unauthenticated Very High Frequency Data Link messages.\nThe risk implications are substantial, as successful exploitation undermines the integrity and trustworthiness of modern digital aeronautical communications.\nAttacker capabilities include remote exploitation over radio frequency without requiring prior authentication, specialized system privileges, or physical access to the aircraft.\nExploitation requirements are limited to possessing compatible radio frequency transmission hardware capable of broadcasting validly formatted Very High Frequency Data Link signals within range of the target aircraft's receiver.",
"technicalDetails": "The root cause of the vulnerability stems from an architectural deficiency in legacy and current Very High Frequency Data Link (VHDL) communication protocols, which inherently lack cryptographic integrity checks, message authentication codes (MACs), or digital signature verification mechanisms for Controller-Pilot Data Link Communications (CPDLC) traffic.\nThe vulnerable component is the aviation data link processing subsystem responsible for receiving, parsing, and presenting Very High Frequency Data Link messages to flight crews.\nNetwork exposure is entirely wireless and remote, operating over radio frequency (RF) spectrums utilized for aeronautical mobile route service (AMR(S)) communications.\nAuthentication requirements are nonexistent for incoming broadcast messages, and no privilege requirements are necessary for an external entity to transmit signals over the air interface.\nThe exploitation method relies on radio frequency transmission where an adversary sets up a rogue ground station capable of generating and broadcasting synthetic Very High Frequency Data Link frames.\nThe step-by-step attack flow proceeds as follows: First, the attacker identifies the active frequencies and network parameters used by aircraft within a specific airspace sector for data link communications. Second, the adversary crafts malicious CPDLC payloads containing unauthorized flight clearances, trajectory modifications, or system commands formatted to mimic legitimate Air Navigation Service Provider (ANSP) transmissions. Third, the rogue ground station transmits these crafted messages over the air via radio frequency. Fourth, the target aircraft's airborne data link transceiver receives the RF transmission and passes the message to the internal avionics processing unit. Fifth, because the protocol lacks authentication, the avionics system accepts and processes the message as authentic. Finally, the injected CPDLC message is displayed to the flight crew or automatically integrated into flight management systems as a valid clearance, leading to unexpected aircraft behavior, pilot confusion, and compromised situational awareness."
}