HIGH

CVE-2025-71409

2026-08-07 CVSS v3.1
CVSS
7.1

Description

Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. This type of attack can be carried out remotely over radio frequency.

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

0.2%
Probability of exploitation in next 30 days
10.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE