What is CVE-2025-71409?
CVE-2025-71409 refers to a lack of authentication for Very High Frequency Data Link messages, allowing rogue ground stations to inject CPDLC messages. This can lead to unexpected or misleading clearances and cause pilot confusion, with the attack executable remotely over radio frequency. Mitigation requires network-level monitoring to detect and block anomalous transmissions.
Azərbaycanca: CVE-2025-71409 çox yüksək tezlikli (VHF) məlumat bağlantısı mesajlarında autentifikasiyanın olmamasıdır. Bu zəiflik saxta yer stansiyalarına CPDLC mesajları yeritməyə imkan verir ki, bu da pilotlar üçün yanıltıcı və ya gözlənilməz icazələrə səbəb ola bilər. Radio tezliyi üzərindən uzaqdan həyata keçirilə bilən bu hücumu önləmək üçün şəbəkə səviyyəsində monitorinq tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
What does CVE-2025-71409 allow?
This vulnerability allows rogue ground stations to inject CPDLC messages, which can lead to unexpected or misleading clearances and cause pilot confusion.
What mitigation is required for CVE-2025-71409?
Mitigation requires network-level monitoring to detect and block anomalous transmissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.