Daily Specs
Security & Privacy
Published on 2026-08-15Updated on 2026-08-15

Boeing 737 Hacked: Unpacking ACARS Vulnerabilities

Original Discovery & Demo Year2013 (Hugo Teso, Hack In The Box / CyberCBR)
Primary Vulnerable SystemAircraft Communications Addressing and Reporting System (ACARS)
Affected Aircraft Type (Demo)Boeing 737 (Flight Management System)
ACARS Operating Frequency BandVHF (Very High Frequency), primarily 118-137 MHz
Detailed technical specification diagram for Coin-sized device can hack a Boeing 737

Key Takeaways

  • In 2013, Hugo Teso demonstrated a proof-of-concept hack on a Boeing 737 Flight Management System using a simulated ACARS device.
  • The vulnerability exploited the legacy ACARS protocol's lack of strong authentication and encryption, allowing forged message injection.
  • The attack, while theoretical and conducted in a lab, highlighted significant security gaps in critical aviation communication systems.
  • Industry and regulatory bodies have since focused on enhancing cyber-physical security for avionics, though legacy systems persist.
Advertisement

Technical Specifications & Data

Original Discovery & Demo Year2013 (Hugo Teso, Hack In The Box / CyberCBR)
Primary Vulnerable SystemAircraft Communications Addressing and Reporting System (ACARS)
Affected Aircraft Type (Demo)Boeing 737 (Flight Management System)
ACARS Operating Frequency BandVHF (Very High Frequency), primarily 118-137 MHz
Core Protocol StandardARINC 618, ARINC 702A
Key Security VulnerabilityLack of strong authentication, absence of encryption (cleartext messages)
Attack VectorInjection of forged ACARS data link subnetwork (ADLS) messages
Potential Malicious ActionsModification of flight plan (waypoints, altitude, speed), manipulation of vertical/lateral navigation
Proof-of-Concept Hardware ConceptSoftware-Defined Radio (SDR) platform, microcontroller, VHF antenna
Regulatory Body Advisory (Post-Demo)EASA Safety Information Bulletin (SIB) 2013-03
Current Mitigation EffortsACARS-NG (IP-based, encrypted), enhanced ground station security, ARINC 841
Relevant Software Assurance StandardRTCA DO-178C

The Theoretical Threat: Hacking a Boeing 737's Avionics

In 2013, security researcher Hugo Teso captivated the cybersecurity world with a presentation detailing how a small, custom-built device could theoretically exploit vulnerabilities in the Aircraft Communications Addressing and Reporting System (ACARS) to manipulate a Boeing 737's Flight Management System (FMS). This groundbreaking demonstration, which involved a custom Android application and a simulated radio interface, showcased the potential to send forged messages to an aircraft, altering flight plans, modifying navigation points, or even dictating altitude and speed parameters. While Teso's work was conducted in a laboratory environment, using flight simulators and mock FMS systems rather than live aircraft, it served as a stark warning about the unaddressed security weaknesses within foundational aviation technologies.

The 'coin-sized device' aspect refers to the miniaturized nature of radio transceivers and microcontrollers available today, suggesting that the necessary hardware to interface with ACARS frequencies could be made incredibly compact. This concept underscored the accessibility of such an attack vector if the protocol weaknesses were left unaddressed. The implications were profound: if an attacker could inject unauthorized commands into an aircraft's FMS, they could potentially compromise the safety and integrity of a flight, raising serious questions about air travel security and the robustness of integrated avionics systems against sophisticated cyber threats. The discussion generated by Teso's work forced a global re-evaluation of how secure aviation's digital backbone truly was.

Why This Matters & Unique Technical Insights

Teso's 2013 findings are crucial because they expose fundamental architectural weaknesses in a system that underpins global air travel: ACARS. Operating primarily over Very High Frequency (VHF) radio links (specifically in bands like 131.55 MHz and 131.725 MHz in North America, with a global range between 118-137 MHz), ACARS predates modern cybersecurity considerations. The protocol, largely defined by ARINC 618, relies on cleartext messaging, lacking robust cryptographic authentication or encryption. This means that messages transmitted between aircraft and ground stations, which include flight plan updates, weather data, and operational messages, are susceptible to interception, modification, and injection by anyone with the right radio equipment and technical know-how.

The FMS, which controls the aircraft's vertical and lateral navigation, relies heavily on these ACARS messages for critical updates. By injecting forged ACARS messages that simulate legitimate ground station commands, an attacker could theoretically overwrite the active flight plan with malicious waypoints, altitude constraints, or speed adjustments. For instance, commands typically used to update navigation databases (e.g., ARINC 702A FMS units) could be hijacked. While the pilots would likely receive alerts or notice discrepancies, the potential for confusion and distraction in critical flight phases is a severe safety concern. The simulated 'coin-sized' device would fundamentally comprise a Software-Defined Radio (SDR) platform (e.g., conceptually similar to a HackRF or USRP) with a compact antenna and a small microcontroller, programmed to understand and generate ACARS data link subnetwork (ADLS) messages. This technical capability highlights the growing vulnerability of legacy cyber-physical systems to modern, accessible hacking tools, emphasizing the urgent need for a shift towards secure-by-design principles in avionics rather than relying on assumed physical isolation.

The Evolution of Avionics Security & Mitigation Strategies

Since Teso's demonstration, the aviation industry, alongside regulatory bodies like the European Union Aviation Safety Agency (EASA) and the Federal Aviation Administration (FAA), has significantly increased its focus on aviation cybersecurity. In response to such findings, EASA issued Safety Information Bulletin (SIB) 2013-03, acknowledging the vulnerabilities and urging operators to assess their systems. However, implementing comprehensive changes across an entire global fleet is a monumental task, especially for legacy aircraft that may lack the hardware or software capacity for significant security upgrades.

Mitigation strategies have focused on several fronts. Firstly, enhancing the security of ground-based ACARS infrastructure to detect and filter suspicious messages. Secondly, exploring and implementing more secure communication protocols. ACARS-NG (Next Generation), which incorporates IP-based communication and stronger cryptographic protections, is under development and gradual rollout. This transition, guided by standards like ARINC 841, aims to replace the vulnerable legacy system. Furthermore, increased emphasis is placed on the security assurance levels during the development of new avionics systems, adhering to rigorous standards like RTCA DO-178C for software and DO-254 for hardware design assurance. While new aircraft benefit from these advancements, a significant portion of the global fleet still relies on older, less secure ACARS implementations. The ongoing challenge lies in balancing the operational needs of a vast and diverse aviation ecosystem with the imperative for robust cybersecurity against evolving threats.

Enhance your digital defense; explore advanced cybersecurity training and secure network solutions.

Chronological Timeline

2013-04

Hugo Teso presents 'Aircraft Hacking: Hacking a Boeing 787 and Airbus A320' at Hack In The Box, detailing ACARS vulnerabilities.

2013-05

European Union Aviation Safety Agency (EASA) issues SIB 2013-03, acknowledging potential vulnerabilities and recommending operator assessments.

Ongoing

Development and gradual implementation of ACARS-NG and other IP-based, secure communication systems in newer aircraft.

Present Day

Legacy ACARS systems remain operational on many existing aircraft, continuing to pose a security challenge.

Frequently Asked Questions

Could a coin-sized device actually hack a real Boeing 737 in flight?
While Hugo Teso's demonstration in 2013 showed the theoretical possibility in a lab, a real-world hack in flight would face significant practical and operational challenges beyond just the technical protocol vulnerability.
What is ACARS and why is it vulnerable?
ACARS (Aircraft Communications Addressing and Reporting System) is a digital datalink system for transmitting short messages between aircraft and ground stations. It's vulnerable because its original design predates modern cybersecurity and lacks encryption and strong authentication.
Are modern aircraft safe from this type of attack?
Newer aircraft and communication systems (like ACARS-NG) incorporate enhanced security measures. However, a significant portion of the global fleet still relies on legacy ACARS, presenting an ongoing challenge for aviation cybersecurity.
Who is Hugo Teso and what was his motivation?
Hugo Teso is a cybersecurity researcher and commercial pilot who demonstrated the ACARS vulnerabilities to highlight critical security gaps in aviation systems and prompt the industry to address them.
PK

Prawin Kannan

Lead Systems & Hardware Analyst

Verified Expert

Prawin specializes in hardware benchmarking, distributed computing infrastructure, and compiler design. He compiles and verifies emerging technical specifications from public repositories and hardware datasheets to provide high-gain technical intelligence.

Advertisement

Related Technical Specs