CVE-2025-1727Active Exploitation

MEDIUMCVSS 7.2 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The protocol used for remote linking over RF for End-of-Train and Head-of-Train (also known as a FRED) relies on a BCH checksum for packet creation. It is possible to create these EoT and HoT packets with a software defined radio and issue brake control commands to the EoT device, disrupting operations or potentially overwhelming the brake systems.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1390

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Exploit tooling references are present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-01-29); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-01-29: 1Mentions · 2026-04-30: 1Mentions · 2026-09-08: 1Exploit Tool / Code · 2026-01-29: 1Active Exploitation · 2026-01-29: 1Technical Details · 2026-04-30: 1Technical Details · 2026-09-08: 101-2904-3009-08
Signal classification3 categories
Active Exploitation
133.3%
General
133.3%
Disclosure
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-291
Active Exploitation1
2026-04-301
General1
2026-09-081
Disclosure1
Full discourse3 posts
  • AKMSecure@akmcyber
    Disclosure

    The protocol controlling US train brakes authenticates commands with a checksum. CVE-2025-1727, CVSS 7.2.     A software-defined radio can forge the packet.  Every DOT mode has a version of this problem. https://na2.hubs.ly/H07GCQG0

    Post summary

    The text announces CVE‑2025‑1727, a checksum authentication flaw in U.S. train braking protocols that allows packet forging via software‑defined radio; it provides basic technical details but no PoC, exploit code, patch, or evidence of active exploitation.

    0001022
    6 followersView on X
  • Austin Causey@AmericanCausey
    Active Exploitation

    Tactical Concern: "Vulnerability Convergence" The cell is exploiting a critical vulnerability in the End-of-Train (EoT) and Head-of-Train (HoT) remote linking protocols (CVE-2025-1727). The Exploit: By using Software Defined Radios (SDR) running MillenniumOS v1.6, the cell can "ping" freight trains passing through rural Montana or North Dakota. The Result: They can essentially "ghost-track" their own shipments across the country without ever accessing the rail company’s internal servers, ensuring their supplies are never lost or seized by automated rail security. 4. Operational Assessment: A "High-Tier" Domestic Threat The scale of this logistical network—stretching from the Puget Sound to the East River and backed by international radical funding—upgrades the Thorne/Sullivan/Aris nexus to a "Tier 1 National Security Threat." This is no longer an activist group; it is a professionalized insurgent force utilizing "State-Level" logistical strategies.

    Post summary

    The text reports that a cell is actively exploiting CVE-2025-1727 using SDRs to track trains, indicating real‑world exploitation but lacking patch or detailed technical information.

    1000042
    1.9K followersView on X
  • @pedri77@pedri77
    General

    A 20-year-old flaw in End-of-Train and Head-of-Train systems could let hackers trigger emergency braking, finally getting proper attention. US CISA has warned about a critical flaw, tracked as CVE-2025-1727, in the radi... https://f.mtr.cool/aoqdkwxarr

    Post summary

    A 20‑year‑old flaw (CVE‑2025‑1727) in train control systems could allow unauthorized emergency braking, prompting a US CISA warning, but no patches, PoC, or active exploitation details are provided.

    00000610
    2.1K followersView on X

Explore more