AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2025-71409

HIGH · CVSS 7.1 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability allows unauthorized ground stations to inject misleading Controller-Pilot Data Link Communications (CPDLC) messages due to a lack of authentication in Very High Frequency Data Link systems. This could lead to unexpected clearances and confusion for pilots, posing significant safety risks. Aviation authorities and operators of affected communication systems should prioritize addressing this issue to safeguard flight operations.

CVE
CVE-2025-71409
Severity
HIGH
CVSS
7.1
EPSS
0.20%

Original NVD Description

Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. This type of attack can be carried out remotely over radio frequency.