{
  "id": 3523139,
  "title": "FURUNO FA-50: Hard-coded Credentials and Missing Authentication for Certain Settings (CVE-2026-59769 / CVE-2026-67578)",
  "url": "https://urgent.news/2026/08/26/furuno-fa-50-hard-coded-credentials-and-missing-authentication-for",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-26T14:13:23.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/furuno-fa-50-hard-coded-credentials-and-missing-authentication-for-certain-settings-3jce"
  },
  "original_language": "en",
  "account": "The FURUNO ELECTRIC FA-50 CLASS B AIS TRANSPONDER, a model in the FA-50 series, suffers from two security vulnerabilities as identified by CVE-2026-59769 and CVE-2026-67578. These flaws affect all versions of the FA-50, with no patches available since the equipment has reached End-of-Life status.\n\nThe first vulnerability, CVE-2026-59769, involves the product using hard-coded credentials, leaving it vulnerable to unauthorized access from within the vessel's internal network. An attacker who gains access can learn these credentials and use them to change settings, including identification numbers.\n\nThe second vulnerability, CVE-2026-67578, involves missing authentication for certain configuration settings. An attacker who can reach the FA-50 management interface without needing authentication can alter specific configuration parameters.\n\nBoth vulnerabilities require the attacker to have access to the vessel's internal network. The exact methods of initial entry are not specified in the public advisories, which do not reveal details about the initial infection vector, management screen URI, communication protocol details, or specific exploitation steps.\n\nWhile the vulnerabilities can result in significant changes to the FA-50's configuration, it is unclear from public information which screens or warnings would alert users to such changes. Administrators are advised to monitor management traffic and discrepancies in settings, though the level of audit logs provided by the product is not specified.\n\nThe vulnerabilities carry a high severity rating and do not pose a direct threat to navigation, safety, collision avoidance, or external monitoring. However, the unauthorized modification of identification numbers or configuration parameters could indirectly impact these areas if left unchecked.\n\nTo mitigate the risks, the FA-50 should not be connected directly to the internet, as recommended by the vendor. The vessel should be securely managed to prevent unauthorized access to the internal network. Additionally, communication sources should be limited to the minimum necessary and restricted management sources should be implemented to enhance security.",
  "summary": "1. Basic Information Article Title : FURUNO ELECTRIC FA-50 CLASS B AIS TRANSPONDER uses hard-coded credentials and misses authentication for additional configuration Source : JVN Publication Date : 2026-08-25 Original Article : JVN Related Sources : FURUNO ELECTRIC , CISA ICS Advisory Related Malware, Threat Groups, CVEs, and Products : CVE-2026-59769, CVE-2026-67578, FURUNO FA-50 CLASS B AIS…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}