All Trains in the USA are vulnerable to wireless RF command injection

2 neilwillgettoit 2 7/11/2025, 5:30:47 PM cisa.gov ↗

Comments (2)

neilwillgettoit · 17h ago
I originally reported this to ICS-CERT in 2012. The American Association of Railroads denied, deflected, and dismissed the claims for 13 years until CISA finally agreed with me that publication was the only option left to pressure the rail industry to fix this vulnerability. This vulnerability is still unfixed in the USA and all rail operations are vulnerable to it. This could lead to inducing brake failures that could cause a derailment and the ability for anyone to shutdown all rail operations across the USA.
neilwillgettoit · 17h ago
https://github.com/ereuter/PyEOT - Eric did a great job breaking down the protocol that was impacted.