What is CVE-2025-71412?
CVE-2025-71412 is a vulnerability allowing the injection of false emergency or status messages over CPDLC. This can lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic controllers, and ground operations. Mitigation requires implementing message integrity verification measures for CPDLC communications to prevent remote attacks carried out over radio frequency.
Azərbaycanca: CVE-2025-71412, CPDLC üzərindən saxta fövqəladə vəziyyət və status mesajlarının ötürülməsinə imkan verən bir zəiflikdir. Bu, uçuş heyəti, hava hərəkət nəzarətçiləri və yerüstü əməliyyatlar arasında resursların yanlış bölüşdürülməsinə, əməliyyat qarışıqlığına və səhv cavab hərəkətlərinə səbəb ola bilər. Radio tezliyi üzərindən uzaqdan həyata keçirilə bilən bu hücumun qarşısını almaq üçün CPDLC kommunikasiyasının bütövlüyünün yoxlanması tədbirləri görülməlidir.
FAQ2
How is the attack exploiting CVE-2025-71412 carried out?
The attack can be carried out remotely over radio frequency by injecting false emergency or status messages over CPDLC.
What potential impacts can result from the exploitation of CVE-2025-71412?
This vulnerability can lead to misallocation of resources, operational confusion, and improper response actions among flight crews, air traffic controllers, and ground operations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.