FURUNO FA-50: Hard-coded Credentials and Missing Authentication for Certain Settings (CVE-2026-59769 / CVE-2026-67578)
1. Basic Information Article Title : FURUNO ELECTRIC FA-50 CLASS B AIS TRANSPONDER uses hard-coded credentials and misses authentication for additional configuration Source : JVN Publication Date : 2026-08-25 Original Article : JVN Related Sources : FURUNO ELECTRIC , CISA ICS Advisory Related Malware, Threat Groups, CVEs, and Products : CVE-2026-59769, CVE-2026-67578, FURUNO FA-50 CLASS B AIS…
The FURUNO ELECTRIC FA-50 CLASS B AIS TRANSPONDER, a model in the FA-50 series, suffers from two security vulnerabilities as identified by CVE-2026-59769 and CVE-2026-67578. These flaws affect all versions of the FA-50, with no patches available since the equipment has reached End-of-Life status.
The first vulnerability, CVE-2026-59769, involves the product using hard-coded credentials, leaving it vulnerable to unauthorized access from within the vessel's internal network. An attacker who gains access can learn these credentials and use them to change settings, including identification numbers.
The second vulnerability, CVE-2026-67578, involves missing authentication for certain configuration settings. An attacker who can reach the FA-50 management interface without needing authentication can alter specific configuration parameters.
Both vulnerabilities require the attacker to have access to the vessel's internal network. The exact methods of initial entry are not specified in the public advisories, which do not reveal details about the initial infection vector, management screen URI, communication protocol details, or specific exploitation steps.
While the vulnerabilities can result in significant changes to the FA-50's configuration, it is unclear from public information which screens or warnings would alert users to such changes. Administrators are advised to monitor management traffic and discrepancies in settings, though the level of audit logs provided by the product is not specified.
The vulnerabilities carry a high severity rating and do not pose a direct threat to navigation, safety, collision avoidance, or external monitoring. However, the unauthorized modification of identification numbers or configuration parameters could indirectly impact these areas if left unchecked.
To mitigate the risks, the FA-50 should not be connected directly to the internet, as recommended by the vendor. The vessel should be securely managed to prevent unauthorized access to the internal network. Additionally, communication sources should be limited to the minimum necessary and restricted management sources should be implemented to enhance security.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.