Remote Message Injection Vulnerability in Air Traffic Control Systems by CISA
CVE-2025-71412

7.1HIGH

Key Information:

Vendor

Atn-b1

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2025-71412?

This vulnerability allows for the remote injection of false emergency or status messages into Controller-Pilot Data Link Communications (CPDLC) systems. Such an attack can create operational confusion, leading to misallocation of resources and inappropriate response actions from flight crews, air traffic controllers, and ground operations. With the potential for exploitation over radio frequencies, this vulnerability poses significant risks to air traffic safety and management.

Affected Version(s)

CPDLC All versions

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Martin Strohmeier of Armasuisse reported this vulnerability to CISA.
.