Coin-Sized $100 Device Exposes New Aircraft Cyber Risk
A coin-sized device costing about $100 has demonstrated a new potential cybersecurity threat to commercial aircraft, allowing researchers to interfere with signals between avionics systems through a maintenance connector. The technique was demonstrated using a Boeing 737 avionics testbed, but the broader concern extends to the physical security of aircraft systems.
A small, inexpensive device has exposed a potentially significant new attack surface in commercial aviation: maintenance connectors that can provide access to aircraft avionics. Researchers from the University of California San Diego and Oberlin College say their proof-of-concept showed how a device costing roughly $100 could be installed in about a minute and used to interfere with signals carrying information between flight systems.
The research does not establish that commercial aircraft are currently being targeted or that passengers face an immediate danger. Instead, it demonstrates how a relatively simple physical attack could potentially manipulate information presented to pilots or used by onboard systems. The Boeing 737 was used as the test platform because of its widely deployed avionics architecture, but the researchers’ broader concern is the security of aircraft systems that rely on similar communication interfaces.
A Small Device With a Large Potential Impact
The device was designed to connect to an Open Maintenance Connector (OMC), an interface intended to allow ground personnel to connect diagnostic equipment to an aircraft’s avionics. Researchers found that the connection could also be used as a point from which to interfere with communications between aircraft computers.
The attack takes advantage of the relatively low power of the legitimate electrical signals moving through the avionics communication system. By transmitting a stronger signal at the appropriate time, the research device can effectively overpower the original transmission and introduce a competing message.
That could allow information from one aircraft computer to be altered before it reaches the system responsible for displaying information in the cockpit. In the researchers’ demonstration, the technique could affect data such as aircraft weight and flight-path information, creating a situation in which different systems could effectively be working with different information.
The Boeing 737 Was the Test Case
To demonstrate the concept, the researchers built a model of Boeing 737 avionics using genuine aircraft components and software. The test was conducted on that controlled setup rather than on an operational aircraft carrying passengers.
The 737 is one of the world’s most widely used commercial aircraft, making it a significant example for aviation cybersecurity research. But the choice of aircraft does not by itself establish that every 737, or every aircraft using related systems, can be attacked in exactly the same way.
The researchers’ central finding is broader: a maintenance interface that was designed for legitimate servicing can potentially become an attack surface if an unauthorized person gains physical access to it.
Why Physical Access Changes the Threat
Aircraft cybersecurity has traditionally focused heavily on protecting digital systems from unauthorized access. This research highlights a different problem. An attacker would not necessarily need to compromise an airline’s network or establish a remote connection to an aircraft if they could physically reach the relevant avionics equipment.
The researchers say the device can be installed quickly once an attacker has gained the necessary access. That changes the security equation because an operation that previously might have required extensive technical work at the aircraft could potentially be reduced to a brief physical intervention.
In a hypothetical scenario, manipulated flight information could create serious consequences if it were not detected by other aircraft systems or by the crew. Incorrect weight information could affect takeoff calculations, while manipulated navigation data could potentially send an aircraft away from its intended route.
The research therefore raises questions not only about the electronics themselves, but also about airport access controls, aircraft maintenance procedures and the security of areas where avionics equipment can be reached.
Boeing Says Protections Limit Real-World Risk
Boeing was informed about the research years before it became public. The company has said that multiple layers of protection within the aircraft’s design and operating environment provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks.
The researchers also caution against interpreting their work as evidence of an imminent threat to air travel. Their demonstration was conducted in a controlled environment, and successfully carrying out an attack against an operational aircraft would involve additional practical obstacles that were not reproduced in the test.
Instead, the study identifies a vulnerability class that may deserve greater attention as aircraft become increasingly dependent on interconnected electronic systems. The key issue is not that a $100 device can automatically take control of an aircraft, but that a cheap physical device can potentially interfere with trusted information flowing between avionics systems.
A Broader Challenge for Aviation Cybersecurity
The findings illustrate how aviation cybersecurity increasingly extends beyond conventional computer networks. Systems that were designed decades ago for maintenance and communication may now have to be evaluated against attack techniques that were not part of their original threat models.
That does not make the Boeing 737 uniquely unsafe, nor does the research establish that aircraft currently in service are routinely exposed to this attack. It does, however, show why physical security and cybersecurity are becoming increasingly interconnected in commercial aviation.
For airlines and regulators, the longer-term question is whether maintenance interfaces and avionics communication systems should incorporate additional safeguards against unauthorized physical access and signal manipulation. The researchers’ work provides a concrete example of why those questions are becoming harder to separate from broader aircraft safety.
