---
title: "For $100 — Control Over a Boeing 737: Researchers Demonstrate an Autopilot Hack via a Service Port"
description: "Researchers demonstrated that the autopilot of a Boeing 737 can be hijacked for less than $100 via a service port. Boeing, which has known about the vulnerability for six years, has still not issued a technical correction."
date: 2026-08-28T16:16:01.000Z
lang: en
url: https://xab.info/en/posts/boeing-737-autopilot-vulnerability-bus-driver-hack
tags: [boeing-737, autopilot-hack, aviation-security, bus-driver, cyber-security, flight-management-computer]
publisher: "XAB.info"
---

# For $100 — Control Over a Boeing 737: Researchers Demonstrate an Autopilot Hack via a Service Port

![Boeing 737 on final approach: researchers demonstrate autopilot hack via service port for $100](https://xab.info/media/2026/08/28/boeing-737-autopilot-vulnerability-bus-driver-hack/boeing-737-autopilot-vulnerability-bus-driver-hack-1.webp)

## 🎯 Key Points

- A device costing less than $100 allows the autopilot of a Boeing 737 to be hijacked via a service port beneath an external access panel
- The Bus Driver technique amplifies the signal on the data bus between the FMC and MCDU, replacing legitimate commands with hacker-controlled ones
- Boeing was informed of the vulnerability six years ago but has not issued a technical correction
- Short-term solution — removing the port or sealing it with epoxy resin; long-term — cryptographic authentication of onboard signals

A group of security researchers has presented a technique that allows the autopilot of a passenger Boeing 737 to be hijacked using a device costing less than $100. The hardware attack, dubbed Bus Driver, gives an attacker the ability to interfere with the onboard computer and distort the data seen by the flight crew. Notably, carrying out the scenario does not require breaching protected avionics systems — physical access to a service port located beneath an unsecured external access panel is sufficient.

### How the Bus Driver Attack Works

The developers built a miniature plug-in with a Wi-Fi module that connects to the onboard service port. The essence of the Bus Driver technique lies in amplifying the electrical signal on the data bus that links the Flight Management Computer (FMC) and the Multipurpose Control Display Unit (MCDU). A data bus is a communication channel — a set of conductors or virtual lines — used to transmit information between the components of an electronic system. By sending pulses with a current exceeding standard parameters, the device jams legitimate commands and replaces them with hacker-controlled ones. Meanwhile, the crew sees fake parameters on the screens that do not reflect the actual flight state.

### Dangerous Scenarios Available to an Attacker

Installing the plug-in opens up a range of critical capabilities. First, a hacker can remotely adjust waypoints in the autopilot, deviating the aircraft from its assigned course, forcing it into the airspace of third countries or into a zone where the aircraft risks running out of fuel. Second, substituting the outside air temperature or total aircraft weight readings leads to an incorrect takeoff acceleration calculation, which can result in the aircraft overrunning the runway. Third, manipulating the data bus blocks the display of fake parameters on the pilot's main screen, creating disorientation in critical situations. Although an experienced pilot can take over control in manual mode, minor adjustments — for example, a course change of a few degrees over the ocean — may go unnoticed until the situation becomes an emergency.

### Contradictory Data

Here a significant discrepancy in assessments arises. Boeing, which the researchers say was informed of the vulnerability six years ago, stated that existing levels of protection substantially limit the feasibility of such attacks under real-world conditions. The company effectively downplayed the scale of the threat, citing architectural barriers. However, despite receiving the notification, the manufacturer has issued no operational technical correction and no service bulletin aimed at eliminating the described vector. The researchers, in turn, emphasize that the discovered scenario requires a review of threat models relevant in the 21st century, and point out that a formal "limitation of feasibility" is not the same as protection. Thus, one side claims the attack is theoretically possible but practically difficult, while the other demonstrates a working prototype for a few dollars and records the absence of any official response from the manufacturer.

### What Is Proposed as a Solution

The researchers identify two levels of measures. The simplest operational solution, they say, is the physical removal of the service port or sealing it with epoxy resin — in effect, eliminating the access point by hardware means. In the long term, in the authors' view, the aviation industry should implement cryptographic authentication of signals within onboard networks, so that any unauthorized interference with the data bus becomes invisible to the attacker and instantly detectable by the crew. Until such measures are implemented, the vulnerability remains open to anyone with basic engineering skills and a device costing less than a hundred-dollar bill.

## 🔍 Fact-Check Verification

- [Boeing 737 autopilot can be broken for $100: researchers show how](https://www.rbc.ua/ukr/news/avtopilot-boeing-737-mozhna-zlamati-100-dolariv-1787920727.html) - Подтверждает стоимость устройства (<100$), название техники Bus Driver, механизм усиления сигнала в шине данных, сценарии атаки и позицию Boeing о шести годах без патча.
- [Can a plane be hijacked in a minute? Researchers find vulnerability in American Boeing 737](https://mosregtoday.ru/articles/interesnoe/samolet-mozhno-ugnat-za-minutu-uchenye-nashli-ujazvimost-v-amerikanskih-boeing-737/) - Подтверждает факт обнаружения уязвимости в Boeing 737 и возможность угona/перехвата управления. Формулировка «за минуту» в заголовке источника не находит прямого подтверждения в основном тексте и не использована в статье.

## ❓ FAQ

### Q: What is Bus Driver and how does it work?
**A:** Bus Driver is a hardware attack technique in which a miniature plug-in with a Wi-Fi module connects to a Boeing 737 service port and amplifies the electrical signal on the data bus between the FMC onboard computer and the MCDU display. Stronger pulses jam the standard commands and are replaced with hacker-controlled ones.

### Q: How much does the attack device cost?
**A:** According to the researchers, the device costs less than $100.

### Q: Why has Boeing not released a fix?
**A:** Boeing, which was informed of the vulnerability six years ago, stated that existing levels of protection limit the feasibility of attacks. However, the company has still not issued an operational technical correction or service bulletin.

### Q: What measures are proposed to eliminate the vulnerability?
**A:** In the short term — physically removing the service port or sealing it with epoxy resin. In the long term — implementing cryptographic authentication of signals within onboard networks.

### Q: Can a pilot prevent the attack?
**A:** An experienced pilot can take over control in manual mode, however minor course adjustments (a few degrees) may go unnoticed until an emergency situation arises.