---
id: CVE-2025-71409
title: >-
  Lack of authentication for Very High Frequency Data Link messages allows rogue
  ground stations to inject CPDLC messages leading to unexpected or misleading
  clearances and potential pilot confusion
summary: >-
  Lack of authentication for Very High Frequency Data Link messages allows rogue
  ground stations to inject CPDLC messages leading to unexpected or misleading
  clearances and potential pilot confusion. This type of attack can be carried
  out …
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L'
cwe:
  - CWE-306
published: '2026-08-07'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:30:43.093'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-71409'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-219-01'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.002
epssPercentile: 0.10146
ingestedAt: '2026-09-08T20:10:03.156Z'
---

## Overview

Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. This type of attack can be carried out remotely over radio frequency.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
