CISA issued an alert detailing two critical FURUNO FA-50 vulnerabilities. These security flaws allow remote attackers to alter maritime device settings without authorization. Administrators must secure physical and network access immediately because the vendor will not release a software update.
- Product: FURUNO ELECTRIC CO., LTD. FA-50
- Vulnerabilities: 2 flaws (CVE-2026-59769, CVE-2026-67578)
- Highest severity: 9.1 (Critical · CVSSv3)
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Fixed in | Status |
|---|---|---|---|
| CVE-2026-59769 | 9.1 | — | Not exploited |
| CVE-2026-67578 | 7.5 | — | Not exploited |
Why It Matters
These FURUNO FA-50 vulnerabilities impact maritime transportation systems worldwide. Maritime vessels rely on AIS transponders for collision avoidance and tracking. Therefore, manipulating this data creates serious safety risks for ship navigation. As the official advisory states, “Successful exploitation of these vulnerabilities could allow an attacker to alter device settings.” Consequently, unauthorized changes to the vessel’s identification number could disrupt critical maritime operations.
How the Attack Works
The first flaw involves the use of hard-coded credentials within the transponder software. An attacker who gains access to the internal vessel network can use these fixed credentials. They then log into the settings screen to modify system parameters. The second vulnerability is a missing authentication check. Because of this flaw, the management interface permits specific configuration changes without requiring any login credentials.
Affected Versions
These FURUNO FA-50 vulnerabilities affect all versions of the Class B AIS Transponder. Production of this specific hardware ended in October 2020. Exact installation counts remain unknown, though the equipment sees worldwide deployment. Currently, official authorities state that “No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.” Furthermore, no public proof-of-concept exploit code exists.
Patch or Mitigation Steps
The vendor will not provide software updates or patches for this legacy equipment. Therefore, teams must apply strict network defenses. Furuno recommends that users never connect the transponder directly to the internet. Furthermore, vessel operators should locate control system networks behind firewalls. They must also ensure the physical vessel remains properly locked and managed to prevent unauthorized local access.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!