HELLFIRE https://www.theregister.com/2025/07/14/train_brakes_flaw/ … The US Cybersecurity and Infrastructure Security Agency (CISA) issued CVE-2025-1727 (CVSS v3.1 8.1) last week, specifying the issue as one of weak authentication in the end-of-train to head-of-train linking protocol - allowing an attacker to input their own braking commands and stop the train in its tracks. … If a savvy person - Smith, for example – used an SDR to snoop on that traffic, they could spoof those packets to tell the FRED to apply the brakes, risking an accident or even potentially a derailment. … So basically for those that never outgrew model trains as kids can now get to play “choo-choo!” with a fullsized one? Asking for a friend… /sarcasm Regards
Somewhat-Reticent SDR is just another tool; as such, it’s innocent and lacks culpability. Insecure “smart” FRED is the crime. ‘“smart” units, which send back data to the crew in the locomotive via radio-based telemetry’ - designed without any thought to security?
broknsymetry HELLFIRE So basically for those that never outgrew model trains as kids can now get to play “choo-choo!” with a fullsized one?