CVE-2025-71410
Received Received - Intake

Unnumbered Disconnect in Aviation VHF Link Control

Vulnerability report for CVE-2025-71410, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: ICS-CERT

Description

Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC functions requiring a reversion to voice communication and increased controller workload. This type of attack can be carried out remotely over radio frequency.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames that can terminate communication sessions. It leads to loss of Controller-Pilot Data Link Communications (CPDLC) functions, forcing a switch back to voice communication and increasing controller workload. The attack can be executed remotely via radio frequency.

Detection Guidance

Detection of this vulnerability requires monitoring for Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames. Use packet capture tools like tcpdump or Wireshark to analyze radio frequency traffic for abnormal session terminations or malformed frames. Check aviation communication logs for unexpected CPDLC function losses.

Impact Analysis

This vulnerability can disrupt critical aviation communication systems, causing loss of data link functions. This may lead to increased reliance on voice communication, higher controller workload, and potential safety risks due to miscommunication or delays in air traffic management.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it pertains to aviation communication systems rather than data privacy or healthcare records. The impact is operational, disrupting air traffic control functions.

Mitigation Strategies

Implement monitoring for unusual Aviation Very High Frequency Link Control frame patterns or session terminations. Ensure redundant communication channels are available to revert to voice communication if CPDLC functions are disrupted.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-71410. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart