Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 07 Aug 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. This type of attack can be carried out remotely over radio frequency. | |
| Title | No Authentication for Very High Frequency Data Link messages used in CPDLC | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-07T19:02:50.109Z
Reserved: 2026-08-04T20:31:35.645Z
Link: CVE-2025-71409
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T21:15:03Z