False Emergency or Status Messages Accepted as Legitimate
CVE:
CVE-2025-71412
Product: ATN-B1 / CPDLC (Controller-Pilot Data Link Communications)
Severity: High 7.1
Published: 07.08.2026
Advisory:
Read the advisory
CPDLC over ATN-B1 accepts injected emergency or status messages as legitimate without adequate checks (CWE-754). Carried out remotely over radio frequency, this may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, air traffic controllers, and ground operations.
CISA ICS advisory: ICSA-26-219-01.