# Cockpit Text Channels Have No Authentication — And Researchers Just Proved You Can Exploit That From the Ground
## The Threat
When a pilot receives a digital clearance to climb to flight level 350, they have no cryptographic way to verify it came from their assigned air traffic controller. That's not a bug introduced recently — it's by design. CPDLC, the Controller-Pilot Data Link Communications system that handles text-based exchanges between pilots and ATC across much of the world, was built on ATN-B1 infrastructure that treats the radio frequency link as inherently trusted. It isn't.
Security researchers have now demonstrated in a controlled lab environment that this trust assumption has real, exploitable consequences. The ATN-B1 CPDLC stack accepts messages from unauthenticated sources, responds predictably to malformed frames, and provides no throttling against floods. That combination opens the door to three attack classes: injected clearances that appear legitimate, session termination that forces a fallback to voice, and denial-of-service conditions that increase controller workload during critical phases of flight.
The vulnerabilities don't create an immediate unsafe condition in the way a control surface failure would. What they do is degrade the safety margin — forcing voice communication reversions, introducing pilot confusion, and compressing the time controllers have to manage traffic. Aviation safety culture calls those conditions "increased risk." Security researchers tend to call them attack primitives.
## Severity and Impact
| CVE | CVSS v3.1 Score | Severity | Vector String | Attack Complexity | Auth Required | CWE |
|---|---|---|---|---|---|---|
| CVE-2025-71409 | 7.1 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L | High | Low Privilege | CWE-306 |
| CVE-2025-71410 | 7.1 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L | High | Low Privilege | CWE-770 |
| CVE-2025-71411 | 7.1 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L | High | Low Privilege | CWE-754 |
| CVE-2025-71412 | 7.1 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L | High | Low Privilege | CWE-306 |
| CVE-2025-71413 | 7.1 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L | High | Low Privilege | CWE-770 |
All five CVEs score identically under both CVSS 3.1 and CVSS 4.0 frameworks, reflecting a consistent attack profile: network-accessible, high complexity, low privilege, no user interaction required, with high integrity impact and scope change.
## Affected Products
The vulnerabilities are protocol-level, not vendor-specific. Any implementation of CPDLC conforming to ATN-B1 is affected:
vers:all/*), as defined by FAA Advisory Circular 90-117 (Data Link Communications)## Mitigations
There are no patches. That's not a temporary gap — there is currently no available fix for any of the five CVEs, because the vulnerabilities are inherent to how the ATN-B1 protocol was designed.
CISA's guidance acknowledges the ceiling:
What operators *can* do is limited but not meaningless:
## References
---
## HackWire Analysis
The CPDLC advisory lands in a year when aviation cybersecurity has moved from theoretical to operationally relevant at a pace that has caught some regulators flat-footed. What's striking here isn't the CVSS score — 7.1 is real but not exceptional — it's the architecture it describes: a global safety-critical communication system running on an unauthenticated protocol by design, with no patch available and no timeline for one.
This is the same structural problem that plagued industrial control systems a decade ago. SCADA protocols like Modbus and DNP3 were built for closed, trusted networks and later got stranded in an internet-connected world without the authentication mechanisms that TCP/IP-era software takes for granted. ATN-B1 CPDLC is following the same arc, just slower because aviation certification cycles are measured in years and aircraft operational lifespans in decades.
The high attack complexity rating deserves scrutiny. "High complexity" in CVSS terms means the attacker needs specific conditions outside their direct control — in this case, proximity to the aircraft's VHF frequency and the ability to transmit at appropriate signal strength. That's a meaningful barrier in routine operations. It's not a barrier for a state actor with access to appropriate radio equipment and airspace access, or for a threat actor targeting a specific high-value flight. The gap between "hard to do from a parking lot" and "hard to do at all" matters enormously for risk assessment in aviation.
The practical near-term action for airlines and ANSPs is procedural: shore up voice communication readiness, train crews on CPDLC anomaly recognition, and pressure avionics vendors for a concrete migration timeline toward authenticated data link protocols. Security doesn't wait for perfect.
— HackWire Editorial
## Related Coverage