CISA Issues Advisory on Five CPDLC over ATN-B1 Vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory regarding five vulnerabilities affecting CPDLC over ATN-B1, a legacy aviation data link protocol. The flaws, tracked as CVE-2025-71409 through CVE-2025-71413, stem from the protocol's reliance on clear text, unauthenticated radio frequency links. Research shows the weaknesses allow unauthorized message injection, denial-of-service conditions, and forced session resets. While the issues do not constitute an unsafe aircraft condition, they can degrade operational safety margins by increasing pilot and controller workload, delaying safety-critical instructions, and reducing situational awareness. No known public exploitation has been reported, but the vulnerabilities are assessed as exploitable in lab environments with high attack complexity.