IM
IronMonkey Threat Research

CVE-2025-71409 HIGH

Published: 2026-08-07 | Last Modified: 2026-08-07 | Status: Received

Description

Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. This type of attack can be carried out remotely over radio frequency.

CVSS Metrics

Base Score: 7.1 (HIGH)

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L

Attack VectorNETWORK
Attack ComplexityHIGH
Privileges RequiredLOW
User InteractionNONE
ScopeCHANGED
Confidentiality ImpactNONE
Integrity ImpactHIGH
Availability ImpactLOW

Source: [email protected]

Type: Secondary

Exploitability Score: 1.8

Impact Score: 4.7

Base Score: 7.1 (HIGH)

CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack VectorNETWORK
Attack ComplexityHIGH
Attack RequirementsNONE
Privileges RequiredLOW
User InteractionNONE
Vulnerability ConfidentialityNONE
Vulnerability IntegrityHIGH
Vulnerability AvailabilityLOW
Subsequent ConfidentialityNONE
Subsequent IntegrityHIGH
Subsequent AvailabilityLOW

Source: [email protected]

Type: Secondary

Weaknesses

Source Type Description
[email protected] Primary
en CWE-306
Notification
Message here