The researchers' custom device, which is roughly the size of a coin (slightly larger than a U.S. quarter), plugs into this port and fits entirely under the existing dust cover, rendering it invisible during casual inspection. The total installation takes under 60 seconds .
Once connected, the device uses a technique the researchers call 'Bus Driver'—sending signals at a higher electrical current to override and replace genuine commands transmitted between the FMC and MCDU. Because the ARINC 429 protocol has no encryption or authentication, the device can intercept, modify, and inject messages without detection . The device also includes a Wi-Fi module, allowing an attacker to control it remotely through an aircraft's onboard Wi-Fi network
.
The 'Bus Driver' device grants an attacker several forms of control over the aircraft's avionics:
The researchers warn that these capabilities could lead to serious outcomes:
Boeing stated it is 'confident that the layers of protection in place on the airplane, including within the system design and the operating environment, provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks' . However, the researchers report that Boeing was first notified of elements of the research more than six years ago, around 2020, and has not disclosed any specific technical fix to address the vulnerability
.
The researchers propose both short-term physical fixes and longer-term engineering solutions:
Short-term physical fixes
Long-term software/hardware fixes
Despite the severity of the demonstration, the researchers emphasize that they continue to fly on Boeing 737s themselves. They are not calling for grounded aircraft but instead advocate for long-term industry planning to address this class of physical-access avionics attacks .