A group of security researchers has presented a technique that allows the autopilot of a passenger Boeing 737 to be hijacked using a device costing less than $100. The hardware attack, dubbed Bus Driver, gives an attacker the ability to interfere with the onboard computer and distort the data seen by the flight crew. Notably, carrying out the scenario does not require breaching protected avionics systems — physical access to a service port located beneath an unsecured external access panel is sufficient.

How the Bus Driver Attack Works

The developers built a miniature plug-in with a Wi-Fi module that connects to the onboard service port. The essence of the Bus Driver technique lies in amplifying the electrical signal on the data bus that links the Flight Management Computer (FMC) and the Multipurpose Control Display Unit (MCDU). A data bus is a communication channel — a set of conductors or virtual lines — used to transmit information between the components of an electronic system. By sending pulses with a current exceeding standard parameters, the device jams legitimate commands and replaces them with hacker-controlled ones. Meanwhile, the crew sees fake parameters on the screens that do not reflect the actual flight state.

Dangerous Scenarios Available to an Attacker

Installing the plug-in opens up a range of critical capabilities. First, a hacker can remotely adjust waypoints in the autopilot, deviating the aircraft from its assigned course, forcing it into the airspace of third countries or into a zone where the aircraft risks running out of fuel. Second, substituting the outside air temperature or total aircraft weight readings leads to an incorrect takeoff acceleration calculation, which can result in the aircraft overrunning the runway. Third, manipulating the data bus blocks the display of fake parameters on the pilot's main screen, creating disorientation in critical situations. Although an experienced pilot can take over control in manual mode, minor adjustments — for example, a course change of a few degrees over the ocean — may go unnoticed until the situation becomes an emergency.

Contradictory Data

Here a significant discrepancy in assessments arises. Boeing, which the researchers say was informed of the vulnerability six years ago, stated that existing levels of protection substantially limit the feasibility of such attacks under real-world conditions. The company effectively downplayed the scale of the threat, citing architectural barriers. However, despite receiving the notification, the manufacturer has issued no operational technical correction and no service bulletin aimed at eliminating the described vector. The researchers, in turn, emphasize that the discovered scenario requires a review of threat models relevant in the 21st century, and point out that a formal "limitation of feasibility" is not the same as protection. Thus, one side claims the attack is theoretically possible but practically difficult, while the other demonstrates a working prototype for a few dollars and records the absence of any official response from the manufacturer.

What Is Proposed as a Solution

The researchers identify two levels of measures. The simplest operational solution, they say, is the physical removal of the service port or sealing it with epoxy resin — in effect, eliminating the access point by hardware means. In the long term, in the authors' view, the aviation industry should implement cryptographic authentication of signals within onboard networks, so that any unauthorized interference with the data bus becomes invisible to the attacker and instantly detectable by the crew. Until such measures are implemented, the vulnerability remains open to anyone with basic engineering skills and a device costing less than a hundred-dollar bill.