A UC San Diego team showed at the USENIX security conference this week that the device slips through a 737's unlocked under nose service hatch and rewrites the autopilot's route while the pilot's display still shows the original.
A team from the University of California San Diego and Oberlin College demonstrated this week at the USENIX Security Symposium in Baltimore that a device the size of a coin and costing less than $100 can be plugged into a Boeing 737 and take over communications between the plane's two key flight computers.
The device targets the data bus between the 737's Flight Management Computer (FMC), which stores the route the autopilot follows, and the Multipurpose Control Display Unit (MCDU), the cockpit panel pilots use to enter and review that route. By sitting on that bus, the implant can rewrite the flight plan and the weight, balance, and outside-air-temperature inputs the autopilot will act on, while suppressing those changes on the pilot's screen. A pilot watching the MCDU would see the original route; the autopilot would fly the rewritten one.
Researchers estimate an attacker would need about 60 seconds of physical access to install the device, through a maintenance port inside the electronics bay under the plane's nose. The port is reached from the ground through an exterior hatch that is not locked and is routinely accessible to maintenance workers and other airport staff, according to the UC San Diego press release and the underlying paper. The device is Wi-Fi enabled, which the researchers say means it could in theory be reached later over the plane's in-flight Wi-Fi network, although the published work does not demonstrate a wireless attack.
The published work is bench-validated against the FMC and MCDU subsystem rather than demonstrated against a flying aircraft. The team frames the demonstration as defensive disclosure. Its stated goal, the researchers write, is to "alert the aviation community to this class of risks, so they may be appropriately mitigated well before they become dangerous." The paper's title is "Design and Implementation of a Physical Implant Attack on the Boeing 737".
The Boeing 737 family numbers roughly 8,000 airframes in service worldwide, according to UC San Diego, with the 737 making up around 25% of Delta's fleet, 38% of American's, and 53% of United's, per the same press release. (The release also refers to the 737 as the entirety of Southwest's fleet; that figure was truncated in the available excerpt and is worth re-confirming before publication.) One maintenance-port access model is therefore a category question for the global fleet, not a curiosity about one airframe.
The researchers' published mitigation is straightforward: lock the maintenance hatch, authenticate devices on the data bus, and separate what the pilot sees from what the autopilot executes so a mismatch is visible. None of those is a new idea in aviation cybersecurity, and none is universally deployed across the 737 family.
The team has now handed that problem to the aviation community. The Boeing 737's electronics bay hatch remains, as of this week, unlocked.