Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-08 ยท updated: 2026-08-08 ยท tags: [cve, ics, aviation, transport, dos, message-injection] ยท confidence: high ยท severity: high ยท affected_sectors: [transport] ยท au_impact: true

CVE-2025-71409 โ€” CPDLC over ATN-B1

CVE-2025-71409 (CVSS 7.1) is one of five CVEs (CVE-2025-71409 through 71413) covered by CISA ICS advisory ICSA-26-219-01, affecting Controller-Pilot Data Link Communications (CPDLC) over the air-traffic-control data link ATN-B1.

Vulnerability Details

Attribute Detail
CVE CVE-2025-71409
CVSS 7.1 (High)
Advisory ICSA-26-219-01
Affected system CPDLC over ATN-B1
Reported by Armasuisse researcher Martin Strohmeier

Nature of the Flaw

The system relies on legacy clear-text, unauthenticated radio-frequency links that allow:

  • Unauthorised message injection
  • Denial-of-service (DoS)
  • Forced session resets in the air-traffic-control data link

CISA notes this does not constitute an unsafe aircraft condition, but can degrade operational safety margins by increasing workload and delaying safety-critical instruction delivery.

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-08