Hacker News .hnnew | past | comments | ask | show | jobs | submitlogin
All Trains in the USA are vulnerable to wireless RF command injection (cisa.gov)
2 points by neilwillgettoit on July 11, 2025 | hide | past | favorite | 2 comments


I originally reported this to ICS-CERT in 2012. The American Association of Railroads denied, deflected, and dismissed the claims for 13 years until CISA finally agreed with me that publication was the only option left to pressure the rail industry to fix this vulnerability. This vulnerability is still unfixed in the USA and all rail operations are vulnerable to it. This could lead to inducing brake failures that could cause a derailment and the ability for anyone to shutdown all rail operations across the USA.


https://github.com/ereuter/PyEOT - Eric did a great job breaking down the protocol that was impacted.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: