illustration of a hand inserting a screwdriver into a Boeing 737's Open Maintenance Connector, with a red callout showing the exposed port

Cleared for Takeover: Researchers Hijack a 737’s Flight Data for Under $20K

Scared to fly? Don’t read this.

Researchers warn 60-seconds of access to a Boeing 737’s critical avionics component could allow a hacker to manipulate data used for aircraft weight balance, flight-plans, and outside temperature readings.

By taking control of the aircraft’s Open Maintenance Connector, a successful attack could leave the plane at risk of being unable to safely take off or allow an adversary to change a flight-plan and trick a pilot into entering another country’s restricted airspace.  

Beyond the Break weekly cybersecurity newsletter — Subscribe

In a research paper presented Thursday at the 35th USENIX Security Symposium in Baltimore a team of computer scientists demonstrated the attacker-in-the-middle hack. Researchers built a small controller that affixes to the Boeing 737’s serial ARINC 429 bus, a component designed in 1977 which facilitates communication between the airplane’s avionics equipment.  

Gone in 60 Seconds

All that’s required is a screwdriver and 60-seconds of access to the Electronic and Equipment (E&E) bay, which houses the avionic component. The latch is accessible from the ground and isn’t secured by a lock, according to UC San Diego researchers Sam Crow, Pat Pannuto, Patrick Mercier, Stefan Savage, Aaron Schulman and Stephen Checkoway of Oberlin College. Each co-authored the paper presented Thursday titled “Design and Implementation of a Physical Implant Attack on the Boeing 737”.

“Using the Boeing 737 as a case study, we document.. [how an attacker] could open the hatch, insert a custom hardware implant into an existing connector, and re-close the hatch easily within 60 seconds,” the researchers explained.

The implant doesn’t reach the plane’s flight-control surfaces directly. Per the paper, it targets the link between the Flight Management Computer (FMC) and the Multi-function Control and Display Unit (MCDU) — the interface pilots use to enter flight plans, waypoints, and weight-and-balance data. By manipulating what passes between the two, the researchers say an implant could feed the flight-management system incorrect data, or conceal changes it has made, without necessarily tipping off the pilot.

In one test, researchers built Wi-Fi connectivity directly into their implant, designed so the device could tap into the plane’s own passenger Wi-Fi network and relay commands over the internet to a remote attacker — allowing real-time manipulation from anywhere in the world. What they didn’t verify is whether a Wi-Fi signal from the cabin would actually reach the implant’s location in the avionics bay below.

A Different Kind of Payload

The “Bus Driver,” as the researchers call it, runs on a commodity ESP32 microcontroller — the kind found in consumer IoT gadgets. Legitimate ARINC 429 transmitters connect through resistors that cap their output near 89 milliamps. The Bus Driver skips them, adds two high-current amplifiers, and pushes 267 milliamps onto the same wire — enough to overpower the real signal. A current sensor lets it read what the legitimate transmitter sent even while overriding it, giving full read-and-rewrite control, not just jamming. Hitting that timing without tripping the plane’s error checks demanded the chip’s max 240 MHz clock speed and its ultra-low-power coprocessor, the only part precise enough to avoid detectable glitches.

The bigger shock is the price and size. Researchers built the entire testbed, including genuine 737 flight-computer and display-unit hardware bought secondhand, for under $20,000. The implant itself shrinks onto a custom circuit board small enough to hide inside its own connector housing, under a dust cap a technician would likely never lift. It draws power straight from the connector, no battery required, whether the plane is parked or flying.

Not Alone in the Friendly Skies

While the hack focused on the Boeing 737, researchers noted that other aircraft could also be vulnerable to a similar attack. “This is not unique to the 737; virtually all transport aircraft have a similar concentration; e.g., the aft avionics compartment on the (Airbus) A320 houses most critical avionics LRUs,” the report stated. Line Replaceable Unit (LRU) is the individual hardware boxes, such as the flight computer or display unit, that make up a plane’s avionics system.

Researchers first disclosed the vulnerability to Boeing in April 2020, followed by several years of briefings, culminating in hardware tests on Boeing’s own 737 testbed in December 2023. Boeing, in turn, disclosed the issue to the Aviation Cyber Initiative, a forum jointly chaired by the FAA, DHS and DoD.

Boeing’s response, included in the report, was that after technical experts reviewed the research it is confident existing safeguards provide a “sufficient mitigation to significantly limit the feasibility and risk of real-world attacks.” It added Boeing takes threats to its products seriously and encourages researchers to disclose concerns responsibly.

Not Exactly In-Flight Entertainment

Legacy vehicle buses have drawn scrutiny before. The most famous example: a 2015 Wired-documented hack in which researchers remotely killed a Jeep’s engine on a highway, exploiting its cellular-connected infotainment system. That stunt triggered a 1.4-million-vehicle recall.

The 737 paper cites older, related academic work too. A 2011 USENIX paper, co-authored by Stephen Checkoway, also an author on the 737 research, showed a car’s CAN bus could be manipulated through its OBD-II diagnostic port. CAN, like ARINC 429, has no built-in authentication. But CAN lets any device transmit freely. ARINC 429 doesn’t. That difference is why the 737 team had to invent a new trick, “Bus Driver,” just to talk over it.

Aviation research has flagged ARINC 429’s weaknesses before, too. Security firm Pen Test Partners has torn down decommissioned airliners in public writeups, including a 747 walkthrough and an Airbus avionics deep dive. Their finding: ARINC 429 predates public-key cryptography entirely. A separate 2024 academic paper demonstrated a denial-of-service attack on a different ARINC 429 link — between a terrain-warning system and a cockpit display. The takeaway: this bus’s lack of authentication is a systemic issue, not one limited to the flight computer link the 737 researchers examined.

Total
0
Shares
Previous Article
Open back door bearing the WordPress logo with an ominous red glow inside

WordPress ‘Link Factory’ Plugin Wasn’t Vulnerable. It Was a Backdoor, Researcher says

Next Article
Illustration of a researcher using a magnifying glass to inspect red virus icons on one side, and a hand applying a bandage to a blue shield on the other, representing the find-and-fix cycle in AI-driven security.

OpenAI's Co-Founder Dogfoods AI on His Own Site: Finds 13 Flaws

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading