--- date: '2025-07-21' description: CVE-2025-1727 highlights a critical vulnerability in the U.S. and Canadian railway wireless braking systems (EoT/HoT). The protocol relies on a BCH checksum without cryptographic authentication, allowing unauthorized entities with a software-defined radio to send fake emergency brake commands, potentially halting trains. This flaw, lingering for over a decade, lacks a patch and necessitates transitioning to a more secure protocol (IEEE 802.16t) by 2027. The recent Polish attack underscores the urgency for enhanced cybersecurity measures within transportation infrastructure to prevent such exploits. Organizations must reassess protocol trust, RF exposure, and system status vigilance. link: /archive/2025-07-21-vulnerability-that-stops-a-running-train-cervello tags: - critical infrastructure security - CVE-2025-1727 - EoT/HoT system - railway cybersecurity - protocol vulnerabilities - weblog title: Vulnerability that Stops a Running Train ◆ Cervello type: weblog --- {% raw %} Cervello shares some perspective on Neil Smith's EoT/HoT vuln. These folks have been deep into railway security for a long time. --- > This week, a vulnerability more than a decade in the making — discovered by [Neil Smith](https://x.com/midwestneil/status/1943708133421101446?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1943708133421101446%7Ctwgr%5Ee63c080011cb930768c69d534b7f4dee1bd8d989%7Ctwcon%5Es1_&ref_url=https%3A%2F%2Fwww.tomshardware.com%2Ftech-industry%2Fcyber-security%2Fsecurity-vulnerability-on-u-s-trains-that-let-anyone-activate-the-brakes-on-the-rear-car-was-known-for-13-years-operators-refused-to-fix-the-issue-until-now) and Eric Reuter, and formally disclosed by [Cybersecurity & Infrastructure Security Agency (CISA)](https://www.cisa.gov/news-events/ics-advisories/icsa-25-191-10)  — has finally been made public, affecting virtually every train in the U.S. and Canada that uses the industry-standard End-of-Train / Head-of-Train (EoT/HoT) wireless braking system. Neil must have been under a lot of pressure not to release all these years. CISA's role as a government authority that stands behind the researcher is huge. Image how different this would have been perceived had he announced a critical unpatched ICS vuln over xitter without CISA's support. There's still some chutzpa left in CISA, it seems. --- > There’s no patch. This isn’t a software bug — it’s a flaw baked into the protocol’s DNA. The long-term fix is a full migration to a secure replacement, likely based on **IEEE 802.16t**, a modern wireless protocol with built-in authentication. The current industry plan targets 2027, but anyone familiar with critical infrastructure knows: it’ll take longer in practice. Fix by protocol upgrade means ever-dangling unpatched systems. --- > In **August 2023**, Poland was hit by a coordinated radio-based attack in which saboteurs used basic transmitters to send emergency-stop signals over an unauthenticated rail frequency. Over twenty trains were disrupted, including freight and passenger traffic. No malware. No intrusion. Just **an insecure protocol and an open airwave**. ( [BBC](https://www.bbc.com/news/world-europe-66630260)) This BBC article has very little info. Is it for the same reason that it took 12 years to get this vuln published? {% endraw %}