FURUNO FA-50 AIS Transponder Has Unpatched Hard-Coded Credentials Flaws
Two high-severity vulnerabilities, CVE-2026-59769 and CVE-2026-67578, have been disclosed in the FURUNO FA-50 Class B AIS Transponder, affecting all versions of the maritime navigation device. The flaws involve hard-coded credentials and missing authentication for certain configuration functions, potentially allowing an attacker with access to a vessel's internal network to alter identification numbers and other settings. No patches will be issued as the product has reached end-of-life, and no public exploitation has been confirmed so far. FURUNO advises users to avoid direct internet connections, apply physical security controls, and upgrade to the successor model, the FA-70. A CVSS 3.1 score of 9.1 underscores the critical nature of the vulnerabilities, though exploitation requires prior access to the ship's internal network.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in