Loss of CPDLC Functions via Malicious Link Control Frames
CVE:
CVE-2025-71410
Product: ATN-B1 / CPDLC (Controller-Pilot Data Link Communications)
Severity: Medium 5.3
Published: 07.08.2026
Advisory:
Read the advisory
Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate CPDLC sessions over ATN-B1 (CWE-770). An attacker operating remotely over radio frequency can cause a loss of CPDLC functions, forcing a reversion to voice communication and increasing controller workload.
CISA ICS advisory: ICSA-26-219-01.