VYPR
advisoryPublished Aug 25, 2026· 1 source

CISA Warns of Critical Vulnerabilities in FURUNO FA-50 AIS Transponder, No Patches Available

CISA has issued an advisory for two critical vulnerabilities in the FURUNO FA-50 Class B AIS Transponder, which could allow attackers to alter device settings. No patches will be provided as the product is end-of-life.

CISA has alerted users to two critical vulnerabilities affecting the FURUNO FA-50 Class B AIS Transponder, a device used in maritime transportation systems. The vulnerabilities, identified as CVE-2026-59769 (Use of Hard-coded Credentials) and CVE-2026-67578 (Missing Authentication for Critical Functions), could allow an attacker with network access to alter the device's settings.

The first vulnerability, CVE-2026-59769, involves the use of hard-coded credentials. An attacker who knows these credentials and has access to the vessel's internal network can exploit this flaw to access the settings screen and modify device configurations. This could potentially disrupt navigation or communication systems.

Compounding the risk, CVE-2026-67578 allows for critical functions to be altered without proper authentication. This means that certain configurations on the management screen can be changed by an unauthenticated attacker, further enabling unauthorized modification of the transponder's settings.

Both vulnerabilities require network access to the device, meaning an attacker would need to be on the same network as the transponder, such as the internal network of a vessel. The CVSS v3.1 base score for CVE-2026-59769 is a critical 9.1, while CVE-2026-67578 has a high score of 7.5, indicating a significant risk.

FURUNO ELECTRIC CO.,LTD. has stated that production of the FA-50 Class B AIS Transponder ended in October 2020, and consequently, no software updates will be provided to address these vulnerabilities. This leaves affected users with limited mitigation options.

Given the lack of patches, CISA strongly recommends that users avoid connecting the product directly to the internet. Furthermore, securing the vessel on which the product is installed and properly managing access to the internal network are crucial steps to prevent unauthorized access and exploitation.

CISA also reiterates general best practices for Industrial Control Systems (ICS) security, including minimizing network exposure by ensuring devices are not accessible from the internet, locating them behind firewalls, and isolating them from business networks. When remote access is necessary, secure methods like VPNs should be employed, ensuring they are kept updated.

While no public exploitation of these specific vulnerabilities has been reported to CISA at this time, the critical nature of the flaws and the end-of-life status of the product highlight the ongoing challenges in securing legacy operational technology in critical infrastructure sectors like transportation.

Synthesized by Vypr AI