A device no larger than a quarter. Less than $100 to build. Under a minute to install. Yet it can seize control of a Boeing 737’s flight management computer, rewrite its route, falsify critical takeoff data, and feed pilots a convincing lie on their displays. All while remaining hidden under a dust cap on an exterior maintenance port.
Researchers from the University of California San Diego and Oberlin College demonstrated exactly that. Tomorrow they present their findings at the USENIX Security Symposium. The work, detailed in their paper “Design and Implementation of a Physical Implant Attack on the Boeing 737”, reveals a vulnerability rooted in the aircraft’s own maintenance architecture. One that demands attention from manufacturers, airlines, and regulators.
The attack starts on the ground. An adversary opens an unlocked hatch on the 737’s electronics and equipment bay, located near the nose wheel. No special tools required. Fifteen seconds later the port is exposed. The implant slides in. It fits so neatly it can hide beneath the port’s protective cap, evading casual visual checks during routine turnaround. Total time? About 60 seconds.
Once connected, the device exploits the ARINC 429 data bus linking the Flight Management Computer and the Multipurpose Control Display Unit in the cockpit. The FMC handles navigation, autopilot commands, performance calculations. The MCDU serves as the pilots’ interface. The bus carries messages between them. The implant becomes an attacker-in-the-middle. But not through software. Through raw electrical dominance.
The researchers call their technique “Bus Driver.” ARINC 429 uses a twisted-pair wiring with specific electrical characteristics. Transmitters drive signals at certain voltages and currents. The implant, equipped with high-current amplifiers, simply drives harder. It overrides legitimate signals on the bus. It reads responses by measuring current. It spoofs displays, injects commands, alters data. All without triggering obvious failure indicators.
“If you could get 60 seconds with an airplane, what could you do?” asked Stefan Savage, UC San Diego professor and project leader, in an interview with WIRED. “Well, it turns out there’s a port that’s externally accessible. You can get to it with no special tools in about 15 seconds. And you can shove in a piece of electronics a little bigger than a quarter that lets you basically tell the autopilot what to do and lie to the pilot about changes to the flight plan.”
The prototype runs on an ESP32 microcontroller. It includes Wi-Fi. After installation it can beacon and connect to the aircraft’s in-flight entertainment or passenger Wi-Fi network. From there a remote operator, perhaps seated in the cabin or even on the ground, issues commands. Change waypoints. The MCDU shows the original route while the FMC steers elsewhere. Modify zero fuel weight. The system calculates takeoff speeds for a lighter aircraft than reality. Alter assumed outside air temperature. Thrust settings shift. Margins erode.
Such tweaks could cause runway overruns. Or tail strikes. Or gradual course deviations that send a plane hundreds of miles off track over open ocean. The changes appear subtle on screens. Pilots might not notice immediately. The implant can suppress warning lights. It spoofs the data pilots trust.
The research team spent more than a decade reaching this point. It began around 2010 with experiments on car hacking. They wondered if planes faced similar risks. Commercial aircraft cost too much to experiment on directly. So they scoured for used parts. Built a testbed from genuine 737 components, including a GE FMC and MCDU. Assembled wiring that matched the aircraft’s schematics. By 2019 they had a working avionics stack they called Triton.
Then came the breakthrough. While studying credit card skimmers that tap into payment buses, Aaron Schulman, another UCSD professor, saw parallels. “We realized that it’s a reasonable threat for someone to plug a device into a bus and read stuff off of it and potentially even gain control of it,” he told WIRED. “We were like, ‘Wait a minute, we’ve got to rethink everything.’”
They found the vulnerable port in one of the 737’s two E&E bays. One lies ahead of the nose gear. The other behind. Both accessible from outside. The specific connector they targeted carries ARINC 429 traffic between FMC and MCDU. A relay normally switches the MCDU between different computers. The implant exploits that.
In spring 2020 the researchers disclosed their findings to Boeing. They later demonstrated the attack inside a Boeing test facility. Boeing reviewed the material. Its response, shared with WIRED, reads: “Our technical experts are confident that the layers of protection in place on the airplane, including within the system design and the operating environment, provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks.”
The researchers remain unconvinced a software fix alone solves the issue. The vulnerability sits in the physical and electrical design. Their paper proposes several countermeasures. Fill the port with epoxy. Remove the connector entirely. Add galvanic isolation with transformers, similar to the MIL-STD-1553 buses used in military aircraft, which resist this kind of current-based override. Detect anomalies by sampling voltage and current. Implement cryptographic authentication on higher-layer protocols, though key management poses challenges.
Sam Crow, the UCSD student researcher who led prototype development, along with co-authors Stephen Checkoway of Oberlin College, Patrick Mercier, Pat Pannuto, Savage, and Schulman, stress they do not see an imminent threat. “Our goal with our research is to help alert the aviation community to this class of risks, so they may be appropriately mitigated well before they become dangerous,” the paper states. “While we have empirically validated that the attacks in this paper work, we do not believe they represent a threat of imminent concern.”
Yet the demonstration carries weight. Roughly 8,000 Boeing 737s fly today across global fleets. Many serve major carriers. Ground access occurs constantly. Maintenance crews, cleaners, caterers, and ramp workers move around aircraft during short turnarounds. A motivated insider or someone who gains brief ramp access could deploy the implant. Once in place it stays until discovered. Or until the plane reaches a heavy maintenance base where deeper inspections occur.
Beau Woods, a cybersecurity adviser, commented on the practicality in discussions around the research. “It is entirely possible to have someone who is on staff go up to an airplane when it’s on the ground… put this type of thing in there.”
The work builds on earlier aviation security concerns. Past demonstrations showed risks in inflight entertainment systems or wireless connections. Those often required network pivots or software flaws. This attack needs only physical proximity for a short window. No remote code execution. No zero-day in the flight software. Just a simple, cheap hardware implant that exploits the bus architecture itself.
Schulman highlighted one scenario. A plane over the Pacific. The implant diverts it three degrees. The crew sees blue ocean everywhere. Nothing seems wrong until fuel runs low or they approach unexpected airspace. “It could be something as subtle as, you’re in the Pacific, you see blue everywhere, and this diverts you 3 degrees off course, and now you’re in the middle of nowhere.”
Real-world weight and performance errors have caused accidents before. In 2024 a LATAM Boeing 787 suffered a sudden pitch-down after a reported weight input mistake of 100 tons. Earlier incidents include Emirates Flight 407 in 2009 and MK Airlines Flight 1602 in 2004, both involving incorrect takeoff weights that led to tail strikes or crashes. The implant could create similar conditions without any pilot error on the keyboard.
Boeing has not publicly detailed specific fixes implemented since the 2020 disclosure. The researchers note that major changes to avionics architecture prove expensive and time-consuming. Some aircraft still rely on 3.5-inch floppy disks for updates, a reminder of how slowly certain systems evolve. Epoxy in a port offers a cheap interim step. But it complicates legitimate maintenance access. Trade-offs abound.
The paper also contrasts ARINC 429 with more robust designs. Transformer-coupled buses like MIL-STD-1553 naturally resist the Bus Driver attack because they isolate signals electrically. Retrofitting or adopting such standards in commercial fleets would require significant investment. Yet the research shows why such investment might now warrant consideration.
News of the implant spread quickly this week. Coverage in Tom’s Hardware emphasized the device’s ability to remain undetected during inspections and its potential to increase pilot workload through conflicting data. Tech Brew framed the gadget as evidence that aviation cybersecurity requires a modern overhaul. Discussions on X highlighted fears over insider threats at airports and the implications for private jets with similar access points.
Savage and his colleagues continue to fly on 737s. They see the research as a call to action rather than panic. The implant proves a concept. Temporary physical access can undermine systems long assumed protected by their complexity and isolation. Airlines load and unload thousands of flights daily. Ramps bustle with activity. That environment now faces a new class of risk.
Whether Boeing, Airbus, or regulators accelerate changes remains to be seen. The port stays accessible today. The bus remains vulnerable to electrical override. A determined actor with brief access and modest resources could exploit both. The coin-sized device shows how small the barrier has become.
And the sky stays busy. Planes keep landing and departing. But the illusion of perfect physical isolation in avionics just cracked. The industry must decide how to seal it.