CISA Warns of Vulnerabilities in Aviation Data Link Communications
CISA has issued an advisory detailing multiple vulnerabilities in CPDLC over ATN-B1, affecting global aviation data link communications and potentially degrading operational safety.

The Cybersecurity and Infrastructure Security Agency (CISA) has released an advisory highlighting a series of critical vulnerabilities affecting the Controller-Pilot Data Link Communications (CPDLC) system operating over the Aeronautical Telecommunications Network (ATN) Baseline 1 (B1).
These vulnerabilities, cataloged under CVE-2025-71409 through CVE-2025-71413, stem from the protocol's reliance on legacy clear-text, unauthenticated radio frequency links. This inherent weakness allows for malicious actors to potentially inject unauthorized messages, initiate denial-of-service conditions, or force session resets.
While CISA emphasizes that these flaws do not directly create unsafe aircraft conditions, they can significantly degrade operational safety margins. The potential for message injection could lead to unexpected or misleading clearances, causing pilot confusion. Session resets can interrupt critical data link functions, forcing a reversion to voice communications and increasing workload for both pilots and air traffic controllers.
The affected systems include all versions of ATN-B1 CPDLC, as detailed in Advisory Circular 90-117. The vulnerabilities fall under common weaknesses such as Missing Authentication for Critical Functions (CWE-306), Allocation of Resources Without Limits or Throttling (CWE-770), and Improper Check for Unusual or Exceptional Conditions (CWE-754).
Specifically, CVE-2025-71409 addresses the lack of authentication for Very High Frequency Data Link messages, enabling rogue ground stations to inject false clearances. CVE-2025-71410 and CVE-2025-71411 exploit control frames to terminate sessions or disconnect multiple aircraft, respectively. CVE-2025-71412 allows for the injection of false emergency or status messages, potentially leading to misallocation of resources and operational confusion.
CISA notes that these vulnerabilities have a high attack complexity and are primarily exploitable in a lab environment under very specific conditions. Currently, no mitigations are available for these flaws, and no known public exploitation has been reported to CISA. Organizations that observe suspected malicious activity are advised to follow established internal procedures and report findings to CISA.
The widespread deployment of ATN-B1 CPDLC across the global transportation sector means that the potential impact, should these vulnerabilities be exploited outside of a lab setting, could be significant. The reliance on unauthenticated links presents a persistent challenge for securing critical aviation communication infrastructure.
This advisory underscores the ongoing need for robust security measures in aviation systems, particularly those that depend on legacy protocols. The lack of available patches or workarounds highlights the importance of continuous monitoring and threat intelligence sharing within the aviation industry.