ICSA-25-191-10
·
Published 2025-09-18
·
View on CISA ICS-CERT ↗
End-of-Train and Head-of-Train Remote Linking Protocol (Update C)
CVSS 8.1
HIGH
Risk Summary
Successful exploitation of this vulnerability could allow an attacker to send their own brake control commands to the end-of-train device, causing a sudden stoppage of the train which may lead to a disruption of operations, or induce brake failure.
CVEs (1)
Remediations
- The Association of American Railroads (AAR) is pursuing new equipment and protocols which should replace traditional End-of-Train and Head-of-Train devices. The standards committees involved in these updates are aware of the vulnerability and are investigating mitigating solutions.
- The AAR Railroad Electronics Standards Committee (RESC) maintains this protocol which is used by multiple manufacturers across the industry.
- Known affected vendors are:
- Wabtec
- Siemens
- DPS Electronics
- Users of EoT/HoT devices are recommended to contact their own device manufacturers with questions.
- Wabtec directs users to visit their cybersecurity page for additional information.
- Siemens advises users of Trainguard devices to reference the associated security bulletin.
Affected Vendors
Association of American Railroads (AAR)
DPS Electronics
Siemens
Wabtec
Affected Products (11)
Association of American Railroads (AAR)
·
End-of-Train and Head-of-Train remote linking protocol
vers:all/*
Wabtec
·
TrainLink NG End of Train (NGEOT)
vers:all/*
Wabtec
·
TrainLink NG3 ATX End of Train (NG3 EOT)
vers:all/*
Wabtec
·
TrainLink NG4 ATX End of Train (NG4 EOT)
vers:all/*
Wabtec
·
TrainLink NG5 ATX End of Train (NG5 EOT)
vers:all/*
Siemens
·
Trainguard HOT
vers:all/*
Siemens
·
Trainguard EOT
vers:all/*
DPS Electronics
·
DPS 2020-He-LD
vers:all/*
DPS Electronics
·
DPS 2020-He
vers:all/*
DPS Electronics
·
DPS 3030-CM-MAG
vers:all/*
DPS Electronics
·
DPS 3030-I-MAG HTD
vers:all/*
Affected Sectors
Transportation Systems
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more