type: cve ยท created: 2026-08-08 ยท updated: 2026-08-08 ยท tags: [cve, ics, aviation, transport, dos, message-injection] ยท confidence: high ยท severity: high ยท affected_sectors: [transport] ยท au_impact: true
CVE-2025-71409 โ CPDLC over ATN-B1
CVE-2025-71409 (CVSS 7.1) is one of five CVEs (CVE-2025-71409 through 71413) covered by CISA ICS advisory ICSA-26-219-01, affecting Controller-Pilot Data Link Communications (CPDLC) over the air-traffic-control data link ATN-B1.
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2025-71409 |
| CVSS | 7.1 (High) |
| Advisory | ICSA-26-219-01 |
| Affected system | CPDLC over ATN-B1 |
| Reported by | Armasuisse researcher Martin Strohmeier |
Nature of the Flaw
The system relies on legacy clear-text, unauthenticated radio-frequency links that allow:
- Unauthorised message injection
- Denial-of-service (DoS)
- Forced session resets in the air-traffic-control data link
CISA notes this does not constitute an unsafe aircraft condition, but can degrade operational safety margins by increasing workload and delaying safety-critical instruction delivery.
Related Pages
- Cisa Issues Ics Advisory On Cpdlc Over Atn B1 Vulnerabilities Five Cves โ The CISA ICS advisory incident page
Sources: raw/digests/Cyber-Digest-2026-08-08