LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2025-71409

Published
CVSS7.1
Severityhigh
WeaknessCWE-306
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L

Description

Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. This type of attack can be carried out remotely over radio frequency.

References

← Back to the CVE Tracker

Our coverage of CVE-2025-71409

No stories yet. This page updates automatically when we publish reporting that references CVE-2025-71409.