AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2025-71412

HIGH · CVSS 7.1 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability allows for the injection of false emergency or status messages into the Controller-Pilot Data Link Communications (CPDLC) system, potentially leading to misallocation of resources and operational confusion among flight crews and air traffic controllers. This high-severity issue poses significant risks to aviation safety and operational integrity, making it crucial for aviation authorities, airlines, and air traffic management organizations to prioritize mitigation efforts.

CVE
CVE-2025-71412
Severity
HIGH
CVSS
7.1
EPSS
0.18%

Original NVD Description

Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic controllers, and ground operations. This type of attack can be carried out remotely over radio frequency.