Critical Flaws in Aviation's ATN-B1 CPDLC Expose Air Traffic to Remote Attacks
A series of critical vulnerabilities, identified as **CVE-2025-71409** through **CVE-2025-71413**, have been discovered in the **ATN-B1 Controller-Pilot Data Link Communications (CPDLC)** system. These flaws, stemming from the reliance on legacy clear-text and unauthenticated radio frequency links, could enable unauthorized message injection, denial-of-service conditions, and forced session resets, potentially degrading operational safety margins worldwide.
The **ATN-B1 CPDLC** system, a cornerstone of modern air traffic management globally, has been found to harbor significant security weaknesses. While these vulnerabilities are not deemed to create an immediate unsafe aircraft condition, they pose a serious threat to operational safety by increasing pilot and controller workload, delaying safety-critical instructions, and reducing situational awareness.
### The Core Vulnerabilities
The identified vulnerabilities primarily revolve around the lack of authentication and robust error handling in the **ATN-B1 CPDLC** system, which operates over Very High Frequency (VHF) radio links. **Martin Strohmeier** of **Armasuisse** reported these issues to **CISA**.
All versions of **CPDLC** over **ATN-B1** are affected. The **CVSS v3** score for these vulnerabilities is rated at 7.1, indicating a high severity.
### Breakdown of Specific CVEs
#### **CVE-2025-71409**: Missing Authentication for Critical Function
This vulnerability allows rogue ground stations to inject false **CPDLC** messages due to a lack of authentication for **VHF Data Link** messages. Such an attack could lead to unexpected or misleading clearances, causing pilot confusion. This attack can be executed remotely via radio frequency.
**Relevant CWE:** **CWE-306 Missing Authentication for Critical Function**
#### **CVE-2025-71410**: Allocation of Resources Without Limits or Throttling
Malicious actors can exploit malformed **Aviation Very High Frequency Link Control (AVLC)** frames or **Unnumbered Disconnect (U DISC)** commands to terminate **CPDLC** sessions. This forces a reversion to voice communication, significantly increasing air traffic controller workload. This attack is also remotely executable over radio frequency.
**Relevant CWE:** **CWE-770 Allocation of Resources Without Limits or Throttling**
#### **CVE-2025-71411**: Allocation of Resources Without Limits or Throttling
Similar to **CVE-2025-71410**, this vulnerability involves the use of broadcast control frames to simultaneously disconnect multiple aircraft. This could lead to widespread delayed clearances and an overload of air traffic controllers, with attacks carried out remotely over radio frequency.
**Relevant CWE:** **CWE-770 Allocation of Resources Without Limits or Throttling**
#### **CVE-2025-71412**: Improper Check for Unusual or Exceptional Conditions
This flaw permits the injection of false emergency or status messages via **CPDLC**. Such an attack could result in the misallocation of resources, operational confusion, and incorrect response actions by flight crews, air traffic controllers, and ground operations. Remote execution over radio frequency is possible.
**Relevant CWE:** **CWE-754 Improper Check for Unusual or Exceptional Conditions**
#### **CVE-2025-71413**: Improper Check for Unusual or Exceptional Conditions
Malformed or out-of-sequence frames at the **AVLC X.25** layers can trigger repeated session resets. This disruption can lead to increased workload for flight crews and reduced situational awareness, with attacks also feasible remotely via radio frequency.
**Relevant CWE:** **CWE-754 Improper Check for Unusual or Exceptional Conditions**
### Impact on Transportation Systems
These vulnerabilities specifically affect the transportation systems critical infrastructure sector, with deployments worldwide. The global nature of air travel means these issues have far-reaching implications for aviation safety and efficiency. The **Advisory Circular 90-117 Data Link Communications** standard is the affected specification.
### Mitigations and Future Outlook
While the current advisories from **CISA** confirm the existence and impact of these vulnerabilities, details on immediate mitigations are yet to be fully released. The fundamental reliance on unauthenticated clear-text communication in legacy systems like **ATN-B1 CPDLC** highlights a broader challenge in securing critical infrastructure that has evolved over decades. Industry stakeholders will need to collaborate on robust authentication mechanisms and secure communication protocols to safeguard global air traffic from these sophisticated threats.