
While much of aviation cybersecurity focuses on network-based threats, researchers just showed that a physical attack on an airplane may require surprisingly little time or money.
Researchers at the University of California San Diego and Oberlin College built a small, coin-sized device that can take over communications between two key flight computers on Boeing 737 aircraft.
The prototype costs less than $100 to build and can be plugged into a maintenance port inside an electronics bay underneath the plane’s nose. That bay is accessible from the ground through an exterior hatch that is not locked and is routinely opened by maintenance workers and other airport staff.
The researchers estimate that an attacker would only need 60 seconds to install the device. Once inside, the Wi-Fi-enabled hardware could theoretically be controlled remotely over the internet—possibly even through the same in-flight Wi-Fi system used by passengers.
How the hack works
The device targets communication between the aircraft’s Flight Management Computer (FMC) and the Multipurpose Control Display Unit (MCDU). The FMC is responsible for managing the flight plan and provides important information used during takeoff and in-flight navigation. The MCDU is the cockpit interface pilots use to enter and revise the flight plan, waypoints, performance data, and other commands.
By injecting commands into the data connection between these two systems, the device can secretly change a plane’s flight plan while preventing those changes from appearing on the pilot’s display. The researchers described scenarios in which hackers could cause the autopilot to divert the aircraft into another country’s airspace or simply send it off course.
Beyond flight plan manipulation, the device can also tamper with sensor data. The researchers demonstrated that it could alter information about the plane’s weight, balance, and outside temperature, making a takeoff unsafe.
Physical access is the key
The attack relies on a short window of physical access. The researchers emphasize that the 60-second installation time is a realistic goal for a motivated attacker. Maintenance areas are often busy, and a person wearing airport credentials or dressed like a ground crew worker might blend in without drawing attention.
The specific maintenance port used in the attack is inside an electronics bay below the plane’s nose. The bay is designed for routine maintenance, and the hatch is not locked. This means that any individual with access to the apron—janitors, catering staff, baggage handlers, fueling crews, or other contract workers—could potentially open the hatch and install the device.
Once installed, the hardware remains hidden. Because it is connected to the aircraft’s internal avionics bus, it can continue communicating whenever the aircraft’s systems are powered. The research team’s prototype also includes a Wi-Fi radio, which opens the possibility of remote control from outside the aircraft. If the plane is equipped with passenger Wi-Fi, the device may even be able to piggyback on that network to receive commands from anywhere in the world.
Why this is a serious concern
The Boeing 737 is one of the most widely used commercial aircraft in the world, with about 8,000 currently in service, according to UC San Diego. The aircraft makes up roughly 25 percent of Delta’s fleet, 38 percent of American’s fleet, 53 percent of United’s fleet, and all of Southwest Airlines’ fleet. Any vulnerability in the 737 therefore has the potential to affect a huge number of flights.
The researchers say their findings point to a broader cybersecurity risk across the aviation industry. Although the demonstration was conducted on a Boeing 737, the underlying principles—unprotected maintenance ports, trust in internal avionics data buses, and limited physical security around aircraft on the ground—may apply to other aircraft types as well.
Aviation security standards have traditionally focused on the network-based attack surface: electronic flight bags, passenger entertainment systems, Wi-Fi, and satellite communication. But this research highlights that a short but deliberate physical intrusion can bypass many of those protections. It also underscores a broader supply chain and insider-threat problem: airports employ thousands of personnel with varying levels of background checks, and not all ground access is equally monitored.
What the researchers demonstrated
The team built a prototype that costs less than $100, using commercially available components. It is designed to sit on the ARINC 429 data bus, a standard avionics networking protocol used in many commercial aircraft. By listening to traffic on that bus and injecting its own messages, the device can impersonate the FMC or the MCDU.
The findings were presented this week at the USENIX Security Symposium in Baltimore. The paper outlines several attack scenarios:
- Changing the active flight plan so the autopilot flies toward an unintended waypoint or destination.
- Hiding these changes from the pilots by suppressing updates to the display.
- Feeding false performance data, such as incorrect aircraft weight or outside temperature, which could lead to improper takeoff calculations.
- Maintaining persistence inside the system, since the device remains connected and can be activated at a later time.
The researchers also note that an attentive pilot could likely detect and recover from many of these attacks by cross-checking other instruments or using manual controls. However, the risk of confusion during critical phases of flight—especially takeoff and landing—can elevate the danger significantly.
Boeing’s response and open questions
The researchers first alerted Boeing to their findings in 2020 and continued working with the company over the next several years. Still, the researchers say they don’t know whether Boeing has done anything to fix the vulnerability.
Boeing did not immediately respond to a request for comment. But the company later said it had reviewed the researchers’ findings and believes existing safeguards are enough to reduce any risks. “Our technical experts are confident that the layers of protection in place on the airplane, including within the system design and the operating environment, provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks,” Boeing said.
The researchers acknowledge that an attack of this type would require significant planning and engineering expertise. It is not something a random passenger could do. But they argue that motivated adversaries—nation-state intelligence agencies, terrorist groups, disgruntled insiders, or criminal organizations—could develop the required skills and adapt the technique to specific airports and aircraft.
What can be done about it
The researchers propose several practical countermeasures. First, airports and airlines can tighten physical access controls around aircraft on the ground. Limiting which personnel are allowed near the electronics bay, requiring escorts for contract workers, and auditing apron access logs could reduce the opportunity for installation.
Second, the vulnerable maintenance port itself could be physically blocked. Sealing it with epoxy, installing a tamper-evident cover, or removing the port entirely on aircraft that do not need it would make an attack much harder. Because the port is primarily used during maintenance and software updates, there is no operational reason for it to remain open during normal passenger service.
Third, avionics systems could be designed to recognize when an unexpected device is attached to the data bus. Adding authentication or anomaly detection at the protocol level would require more than a simple plug-and-play attack. However, updating decades-old aircraft systems is expensive and requires regulatory approval.
Finally, the broader aviation industry may need to rethink the assumption that physical access is an acceptable risk for critical systems. The researchers’ low-cost demonstration raises uncomfortable questions about how many other flight-critical components are also protected only by the difficulty of reaching them, rather than by active security controls.
The researchers are under no illusion that every attack can be stopped. In their paper, they note that all of the authors routinely travel on Boeing 737 aircraft and expect to continue doing so. That quiet statement captures the reality of aviation security: threats are often difficult to fix quickly, but the public does not stop flying. The goal, the researchers say, is to alert the aviation community to this class of risks so they can be appropriately mitigated well before they become dangerous.
Source:Gizmodo News
