Security/ aviation · boeing · hacking · cybersecurity

Researchers Hack a 737's Flight Computer With a Coin-Sized Device

A tiny device plugged into a hidden diagnostic port can override a Boeing 737's flight computer, and researchers say fixing it won't be quick or cheap.

A coin-sized gadget can plug into a Boeing 737 and hijack its flight computer.

Researchers from UC San Diego and Oberlin College built a small device that attaches to a diagnostic port inside the 737's electronics bay, the same port mechanics use to test the Flight Management Computer (FMC) and its cockpit display, the Multipurpose Control Display Unit (MCDU). The port sits behind a simple dust cap, with no authentication protecting it. Once connected, the device can intercept and alter data flowing between the two systems, changing inputs like outside air temperature or aircraft weight that feed into takeoff performance calculations. The researchers say the device can even reach the internet through in-flight Wi-Fi, letting an attacker tamper with the plane's avionics remotely instead of needing physical access mid-flight.

Bad weight and temperature inputs aren't a hypothetical risk. Real crews have mistyped these numbers by accident, including a 2004 crash involving MK Airlines Flight 1602, where an incorrect weight entry contributed to a Boeing 747 failing to get airborne. This research shows the same kind of failure could be triggered deliberately and quietly by anyone with a few minutes of access to an unguarded panel, and Boeing's response, that layered safety systems make real-world attacks unlikely, is the standard answer vendors give when a hardware exploit surfaces before a fix does.

Pilots are trained to catch conflicting instrument readings and air traffic control offers another backstop, but the fix here is as simple as locking a port and encrypting a bus, and the industry hasn't done it yet.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →