All stories
Big Tech

Coin-Sized Device Can Hack Boeing 737 Flight Computers via Diagnostic Port and Wi-Fi

A coin-sized device, developed by researchers from the University of California San Diego (UCSD) and Oberlin College, has demonstrated the alarming capability to compromise a Boeing 737's Flight Management Computer (FMC), potentially altering critical flight data or even diverting an aircraft.

By TECH NEWS Editorial·Source:Tom's Hardware·4 min read·2h ago

This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more

Share

Listen to this story

0:00 / 0:00
Coin-Sized Device Can Hack Boeing 737 Flight Computers via Diagnostic Port and Wi-Fi

A coin-sized device, developed by researchers from the University of California San Diego (UCSD) and Oberlin College, has demonstrated the alarming capability to compromise a Boeing 737's Flight Management Computer (FMC), potentially altering critical flight data or even diverting an aircraft. This miniature gadget plugs into an easily accessible external diagnostic port, typically used by mechanics, and, critically, leverages the aircraft's in-flight Wi-Fi network to override commands from pilots to the FMC. This revelation exposes a profound vulnerability, shifting aviation cybersecurity concerns from theoretical remote exploits to a tangible, physical threat that demands immediate industry-wide re-evaluation.

The mechanism of this attack is deceptively simple yet devastatingly effective. The device, small enough to be concealed under a dust cap on the diagnostic port, acts as an intermediary, intercepting and manipulating signals between the Multipurpose Control Display Unit (MCDU)—the cockpit terminal pilots use for input—and the FMC, which governs the aircraft's navigation, autopilot, and performance calculations. While the researchers emphasize it doesn't grant full remote control of the aircraft, the ability to inject erroneous data for takeoff weights, manipulate flight plans, or issue diversion commands could severely confuse pilots, drastically increase their workload in a critical phase of flight, and potentially lead to catastrophic safety incidents. The initial research stemmed from car hacking experiments in the mid-2010s, with researchers building a functional avionics stack from readily available parts to prove the concept. The use of in-flight Wi-Fi by the device, once physically connected, highlights how even seemingly isolated critical systems can be bridged to less secure passenger networks, creating an unforeseen attack surface.

This discovery carries immense implications for passengers, airlines, and the entire aerospace industry. For the flying public, it erodes trust in the inherent safety of modern air travel, introducing a new, tangible dimension of threat beyond traditional physical hijacking. The psychological impact of knowing a critical system could be compromised by a tiny, surreptitiously installed device, even if not leading to immediate disaster, is significant. For airlines, the immediate concern is reputational damage, coupled with the potential for substantial financial costs associated with enhanced security protocols, investigations, and liability in the event of an incident. Boeing, as the manufacturer of the widely used 737, faces intense scrutiny regarding the security of diagnostic ports and the segmentation of critical avionics from passenger-facing or maintenance networks.

The broader aviation industry, already grappling with an escalating number of cyber threats—with incidents reported to the Cybersecurity and Infrastructure Security Agency (CISA) rising from 290 in 2020 to 352 in 2025 across the aviation subsector—must confront this new vector. Historically, aviation cybersecurity discussions often revolved around remote hacking of in-flight entertainment systems or vulnerabilities in the Aircraft Communications Addressing and Reporting System (ACARS), an unencrypted digital network susceptible to message manipulation and eavesdropping that is often connected to FMCs. The 2015 incident involving security researcher Chris Roberts, who claimed to have accessed an aircraft's thrust management computer via the in-flight entertainment system, underscored the potential for such cross-system vulnerabilities. However, this new research demonstrates a practical, physical-access method that bypasses the complexities of remote network penetration, directly targeting the avionics bus.

Regulatory bodies like the Federal Aviation Administration (FAA) and the European Union Aviation Safety Agency (EASA) have been proactive, establishing standards such as RTCA DO-326A and DO-356A, and EASA's Rulemaking Task RMT 0648 and 0720, to address airworthiness security requirements and cybersecurity risk assessments. The FAA also published a proposed rulemaking in August 2024 to standardize design standards against cybersecurity threats for new transport category airplanes, engines, and propellers, aiming to reduce certification costs while maintaining safety. These efforts, while crucial, primarily focus on design-level resilience and network segmentation. The discovered vulnerability, however, highlights a gap in physical security oversight for easily accessible maintenance ports that can be exploited in less than a minute.

Moving forward, the industry must implement multi-layered defenses. Immediate steps should include enhanced physical security measures for diagnostic ports, potentially involving tamper-evident seals, robust locking mechanisms, and revised pre-flight inspection protocols to detect any unauthorized attachments. For the long term, aircraft manufacturers must revisit avionics architectures, pushing for stricter network segmentation and the adoption of "zero-trust" principles, where no component is inherently trusted, regardless of its location or perceived isolation. This includes securing debugging and programming ports with fuses or locks to prevent firmware tampering. Furthermore, robust software integrity checks, secure boot mechanisms, and continuous monitoring for anomalous data flows within the FMC and related systems are essential. The interconnectivity of modern aircraft, driven by the demand for efficiency and passenger connectivity, necessitates a holistic security approach that integrates cybersecurity into every stage of design, maintenance, and operation. The FAA's ongoing efforts to integrate cybersecurity into safety management systems, as outlined in their Order 1370.121, will be critical. Ultimately, this coin-sized threat serves as a stark reminder that the battle for aviation security is a continuous, evolving one, requiring unprecedented collaboration between manufacturers, airlines, regulators, and cybersecurity researchers to stay ahead of increasingly sophisticated adversaries.