CVE-2025-71410
Last modified
CVE-2025-71410 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC functions requiring a reversion to voice communication and increased controller workload. This type of attack can be carried out remotely over radio frequency.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC functions requiring a reversion to voice communication and increased controller workload. This type of attack can be carried out remotely over radio frequency.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| ATN-B1 | CPDLC | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-71410?
How severe is CVE-2025-71410?
How do I fix CVE-2025-71410?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-71405chi versions before v5.2.2 contain an open redirect vulnerab…5.1
- CVE-2025-71406Rejected reason: This CVE ID has been rejected as a duplicat…
- CVE-2025-71407Rejected reason: This CVE ID has been rejected as a duplicat…
- CVE-2025-71408NLTK (Natural Language Toolkit) before version 3.9.3 contain…8.5
- CVE-2025-71409Lack of authentication for Very High Frequency Data Link mes…7.1
- CVE-2025-7141A vulnerability classified as problematic was found in Sourc…5.4
- CVE-2025-71411Broadcast control frames can disconnect multiple aircraft si…5.3
- CVE-2025-71412Injection of false emergency or status messages over CPDLC m…7.1
- CVE-2025-71413Malformed or out-of-sequence frames at the Aviation Very Hig…5.3
- CVE-2025-71417PocketMine-MP before 5.32.1 fails to validate uniqueness of …6.5
- CVE-2025-71418PocketMine-MP versions before 5.25.2 fail to limit the explo…5.3
- CVE-2025-71419UVdesk core-framework before 1.1.7 contains a stored cross-s…5.4
Are you affected by CVE-2025-71410?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
