<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>ATN-B1 CPDLC - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/atn-b1-cpdlc/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 07 Aug 2026 19:48:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/atn-b1-cpdlc/feed.xml" rel="self" type="application/rss+xml"/><item><title>Vulnerabilities in ATN-B1 Controller Pilot Data Link Communications (CPDLC)</title><link>https://feed.craftedsignal.io/briefs/2026-08-atn-b1-cpdlc-vulnerabilities/</link><pubDate>Fri, 07 Aug 2026 19:48:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-atn-b1-cpdlc-vulnerabilities/</guid><description>The ATN-B1 CPDLC protocol is susceptible to message injection and denial-of-service attacks due to reliance on unauthenticated, clear-text radio frequency communication.</description><content:encoded><![CDATA[<p>The Controller Pilot Data Link Communications (CPDLC) protocol over Aeronautical Telecommunication Network Baseline 1 (ATN-B1) contains critical design-level vulnerabilities stemming from the use of legacy, clear-text, and unauthenticated radio frequency (RF) links. Researchers identified that these flaws allow for unauthorized message injection, denial-of-service (DoS) attacks, and forced session resets.</p>
<p>Specific vulnerabilities identified include:</p>
<ul>
<li>CVE-2025-71409: Lack of authentication allowing rogue ground station message injection.</li>
<li>CVE-2025-71410: Use of unnumbered disconnect (U DISC) frames to terminate sessions.</li>
<li>CVE-2025-71411: Use of broadcast control frames to disconnect multiple aircraft simultaneously.</li>
<li>CVE-2025-71412: Injection of false emergency or status messages.</li>
<li>CVE-2025-71413: Improper check for unusual or exceptional conditions.</li>
</ul>
<p>While currently observed primarily in lab environments, these vulnerabilities pose a risk to aviation operational safety by delaying safety-critical instructions and increasing cognitive workload for flight crews and controllers. No mitigations are currently available for the affected protocol standards.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities can lead to the compromise of situational awareness, operational delays in air traffic management, and potential misallocation of resources due to the injection of false emergency status messages. These issues impact the global transportation sector, specifically affecting organizations relying on the ATN-B1 CPDLC protocol for pilot-controller communications.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor for anomalous or unexpected CPDLC message traffic patterns within aviation communication systems.</li>
<li>Establish and review internal contingency procedures for manual voice-link reversion in the event of suspected CPDLC session disruption.</li>
<li>Report any suspected RF-based message injection or unsolicited session terminations to relevant national aviation authorities and CISA for correlation.</li>
<li>Review the technical advisories for CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, and CVE-2025-71413 as they become available for updates on mitigation paths.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category></item></channel></rss>