Security researchers from the University of California at San Diego and Oberlin College have detailed a potential vulnerability involving the physical architecture of the Boeing 737. The team developed a compact, low-cost prototype device capable of connecting to an externally accessible maintenance port. According to their presentation at the Usenix Cybersecurity Conference, this method allows for the insertion of signals into the aircraft internal network.
By accessing the network through a hatch, the device can allegedly influence the Flight Management Computer and the Multipurpose Control Display Unit. Researchers stated that this could potentially be used to alter flight plans or spoof data on cockpit displays. The project, which involved building a test bed from secondhand aviation components, spanned several years of development.
Boeing was notified of these findings years ago and conducted internal reviews. The manufacturer stated that existing layers of system design and operational security provide sufficient mitigation against such risks. While the researchers suggest physical access improvements like securing or removing these ports, they emphasized that their findings do not necessitate grounding the fleet. Operators and industry stakeholders continue to monitor developments regarding physical security protocols for commercial aircraft.