CVE-2025-71410 describes a vulnerability that allows remote termination of CPDLC (Controller-Pilot Data Link Communications) sessions over VHF radio frequency. The CVSS 5.3 score is analytically misleading. It treats session termination as the endpoint of concern, but CPDLC is load-bearing communication infrastructure — it exists because voice communication cannot scale to current airspace density. When an attacker forces mass reversion to voice, they are not merely disrupting datalink; they are executing a congestion attack on the airspace's communication backbone. This is the actual impact, and it cannot be captured by scoring individual session terminations.
The attack vector is fundamentally different from network exploitation. This is broadcast-medium interference on a shared VHF frequency — no intrusion, no breach of defenses, no authentication bypass required. The attacker transmits on the same medium that aircraft and ground stations already trust by design. This changes the remediation calculus entirely. Patching software will not fix this. The question is whether VDL Mode 2 protocol has sufficient integrity verification to reject malformed frames, and whether that verification can be strengthened without breaking backward compatibility with legacy avionics that cannot be recertified.
This is not an isolated failure. AIS spoofing and ADS-B injection attacks received similar CVSS-medium scores despite enabling functionally identical attack patterns — forcing systems away from automated data exchange and into congested human-mediated fallback. The pattern reflects a structural inability in the scoring ecosystem to reason about broadcast protocols designed in an era where