← Back to home
ICSA-25-191-10  ·  Published 2025-09-18  ·  View on CISA ICS-CERT ↗

End-of-Train and Head-of-Train Remote Linking Protocol (Update C)

CVSS 8.1 HIGH

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to send their own brake control commands to the end-of-train device, causing a sudden stoppage of the train which may lead to a disruption of operations, or induce brake failure.

CVEs (1)

Remediations

  • The Association of American Railroads (AAR) is pursuing new equipment and protocols which should replace traditional End-of-Train and Head-of-Train devices. The standards committees involved in these updates are aware of the vulnerability and are investigating mitigating solutions.
  • The AAR Railroad Electronics Standards Committee (RESC) maintains this protocol which is used by multiple manufacturers across the industry.
  • Known affected vendors are:
  • Wabtec
  • Siemens
  • DPS Electronics
  • Users of EoT/HoT devices are recommended to contact their own device manufacturers with questions.
  • Wabtec directs users to visit their cybersecurity page for additional information.
  • Siemens advises users of Trainguard devices to reference the associated security bulletin.

Affected Vendors

Association of American Railroads (AAR) DPS Electronics Siemens Wabtec

Affected Products (11)

Association of American Railroads (AAR) · End-of-Train and Head-of-Train remote linking protocol vers:all/*
Wabtec · TrainLink NG End of Train (NGEOT) vers:all/*
Wabtec · TrainLink NG3 ATX End of Train (NG3 EOT) vers:all/*
Wabtec · TrainLink NG4 ATX End of Train (NG4 EOT) vers:all/*
Wabtec · TrainLink NG5 ATX End of Train (NG5 EOT) vers:all/*
Siemens · Trainguard HOT vers:all/*
Siemens · Trainguard EOT vers:all/*
DPS Electronics · DPS 2020-He-LD vers:all/*
DPS Electronics · DPS 2020-He vers:all/*
DPS Electronics · DPS 3030-CM-MAG vers:all/*
DPS Electronics · DPS 3030-I-MAG HTD vers:all/*

Affected Sectors

Transportation Systems

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more