Missing Authentication for Critical Function in VDL Messages
CVE:
CVE-2025-71409
Product: ATN-B1 / CPDLC (Controller-Pilot Data Link Communications)
Severity: High 7.1
Published: 07.08.2026
Advisory:
Read the advisory
Controller-Pilot Data Link Communications (CPDLC) over ATN-B1 does not authenticate Very High Frequency Data Link messages (CWE-306). Rogue ground stations can inject CPDLC messages remotely over radio frequency, leading to unexpected or misleading clearances and potential pilot confusion.
CISA ICS advisory: ICSA-26-219-01.