CVE-2025-71409EPSS p10.0%

CVE-2025-71409CVE-2025-71409

Description

Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. This type of attack can be carried out remotely over radio frequency.

Scoring

CVSS 7.1 ()
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L
EPSS0.20% probability of exploitation · percentile 10.0% · 2026-08-08T12:02:54Z
Last modified2026-08-07
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.