Executive Summary
In November 2025, critical vulnerabilities were publicly disclosed in Radiometrics VizAir, a system widely deployed in global airport transportation infrastructure. The flaws (CVE-2025-61945, CVE-2025-54863, CVE-2025-61956) permit unauthenticated remote attackers to manipulate weather parameters, runway settings, and extract sensitive meteorological data via missing authentication controls and exposed credentials. Exploitation could disrupt airport operations, mislead air traffic control and pilots, and create hazardous flight conditions by disabling vital alerts or injecting false data. The vulnerabilities were reported by a security researcher and were assigned the highest CVSS score of 10.0, reflecting severe risk to operational safety.
This incident highlights the escalating risk facing critical infrastructure as attackers increasingly target operational technology systems with low-complexity, high-impact exploits. Given the global reliance on secure flight operations, the breach underscores the urgency for robust authentication, segmentation, and credential management controls across transportation-critical systems.
Why This Matters Now
Airports and airlines depend on accurate and trustworthy operational data for safety. The Radiometrics VizAir incident demonstrates how trivial authentication flaws in infrastructure technology can rapidly become systemic threats with real-world impact. With attack sophistication and regulatory scrutiny both rising, protecting OT assets against unauthorized access is business-critical right now.
Attack Path Analysis
The attacker remotely identified and gained unauthorized access to the VizAir admin panel due to missing authentication controls and exposed API keys. Leveraging admin-level functions, the adversary escalated privileges by abusing exposed REST APIs and configuration files. They then moved laterally within the environment, potentially accessing additional system components or network-connected weather stations. Establishing command and control, the attacker maintained access and manipulated critical settings and data over time. Sensitive meteorological data was then exfiltrated or altered, impacting operational integrity. Finally, the attacker disrupted airport operations by modifying weather parameters and runway assignments, causing hazardous flight conditions.
Kill Chain Progression
Initial Compromise
Description
Attacker remotely accessed the VizAir admin panel and configuration endpoints due to missing authentication and exposed credentials (API keys), obtaining initial foothold with admin functionality.
Related CVEs
CVE-2025-61945
CVSS 10Radiometrics VizAir allows remote attackers to access the admin panel without authentication, enabling modification of critical weather parameters and runway settings.
Affected Products:
Radiometrics VizAir – < 08/2025
Exploit Status:
no public exploitCVE-2025-54863
CVSS 10Radiometrics VizAir exposes its REST API key through a publicly accessible configuration file, allowing remote attackers to alter weather data and configurations.
Affected Products:
Radiometrics VizAir – < 08/2025
Exploit Status:
no public exploitCVE-2025-61956
CVSS 10Radiometrics VizAir lacks authentication mechanisms for critical functions, allowing attackers to modify configurations without authentication.
Affected Products:
Radiometrics VizAir – < 08/2025
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Unsecured Credentials: Credentials In Files
Modify Control Process
Unauthorized Command Message
Manipulation of View
Data Destruction
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – User Identification and Authentication
Control ID: 8.2.1
PCI DSS 4.0 – Secure Storage of Sensitive Authentication Data
Control ID: 3.4.2
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.02
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – Risk Management: ICT Security
Control ID: Art. 9(2)
CISA ZTMM 2.0 – Authentication Enforcement
Control ID: Identity – Authenticate Devices and Users
NIS2 Directive – Risk Management: Security of Networks and Information Systems
Control ID: Article 21(2)(a)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Airlines/Aviation
Critical aviation weather monitoring systems compromised, enabling manipulation of wind shear alerts and runway assignments, potentially causing hazardous flight conditions and mid-air conflicts.
Aviation/Aerospace
Unauthenticated access to VizAir systems allows attackers to manipulate CAPE values and meteorological data, compromising flight safety and accurate weather forecasting capabilities.
Transportation
Airport operations face significant disruption through false weather alerts and denial-of-service conditions, affecting flight planning, takeoff/landing safety, and air traffic control operations.
Government Administration
CISA advisory highlights critical infrastructure vulnerabilities requiring immediate defensive measures, network isolation, and VPN security protocols to protect transportation system operations.
Sources
- Radiometrics VizAirhttps://www.cisa.gov/news-events/ics-advisories/icsa-25-308-04Verified
- NVD - CVE-2025-61945https://nvd.nist.gov/vuln/detail/CVE-2025-61945Verified
- NVD - CVE-2025-54863https://nvd.nist.gov/vuln/detail/CVE-2025-54863Verified
- NVD - CVE-2025-61956https://nvd.nist.gov/vuln/detail/CVE-2025-61956Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying CNSF controls such as Zero Trust Segmentation, strong east-west policy enforcement, encrypted communications, multi-cloud visibility, and egress controls would have greatly reduced attacker opportunities, detected suspicious activity, and contained the blast radius of the compromise within the cloud network.
Control: Zero Trust Segmentation
Mitigation: Blocked unauthorized access to critical functions and admin interfaces.
Control: Multicloud Visibility & Control
Mitigation: Detected unauthorized invocation of sensitive API operations.
Control: East-West Traffic Security
Mitigation: Prevented lateral movement via microsegmentation of workloads and strict network isolation.
Control: Inline IPS (Suricata)
Mitigation: Detected and blocked suspicious C2 communication attempts.
Control: Egress Security & Policy Enforcement
Mitigation: Stopped data exfiltration attempts over unauthorized or insecure outbound channels.
Rapid detection of abnormal system changes and incident response initiation.
Impact at a Glance
Affected Business Functions
- Air Traffic Control
- Flight Operations
- Weather Forecasting
Estimated downtime: 3 days
Estimated loss: $5,000,000
Potential exposure of sensitive meteorological data, including wind shear alerts, inversion depth, and CAPE values, which are essential for accurate weather forecasting and flight safety.
Recommended Actions
Key Takeaways & Next Steps
- • Segment all critical cloud workloads and management interfaces using Zero Trust Segmentation to restrict unauthorized access.
- • Apply strong east-west policy enforcement to prevent lateral movement between cloud and on-prem systems.
- • Monitor privileged API activity and employ centralized, real-time visibility for all operator actions across environments.
- • Enforce egress controls and encrypted traffic policies to block data exfiltration and ensure secure communications.
- • Deploy inline IPS and anomaly response for rapid detection and containment of unauthorized configuration or data manipulation attempts.



