Attackers can alter settings on Furuno FA-50 AIS transponders via hard-coded credentials
Hard-coded credentials and missing authentication in Furuno FA-50 AIS transponders allow attackers on the internal vessel network to alter device settings and identification numbers. Because production of this hardware ended in 2020, no software patches are coming. Defenders should isolate these devices from the internet and consider migrating to the FA-70 successor.
Summary
The Furuno FA-50 Class B AIS transponder contains critical vulnerabilities that permit unauthorized modification of device settings. An attacker who gains access to the vessel's internal network can use hard-coded credentials to access the settings screen and alter the device's identification number. Additionally, certain configuration options on the management screen are accessible without any authentication.
Technical details
The FA-50 hardware is susceptible to two distinct security flaws. The first, CVE-2026-59769, involves the use of hard-coded credentials (CWE-798). If an attacker knows these credentials and has access to the in-vessel network, they can operate the settings screen to change critical device parameters.
The second vulnerability, CVE-2026-67578, involves missing authentication for critical functions (CWE-306). This flaw allows an attacker to change additional configurations via the management screen without providing any credentials.
Affected products and fixed versions
The vulnerabilities affect all versions of the FA-50 Class B AIS transponder.
| Product | Vulnerability | Severity | Status |
|---|---|---|---|
| FA-50 | CVE-2026-59769 | Critical (9.1) | No patch available |
| FA-50 | CVE-2026-67578 | High (7.5) | No patch available |
Production of the FA-50 ended in October 2020. Consequently, the vendor will not provide software updates or patches for these issues.
Why this matters for defenders
These flaws present a significant risk to vessel integrity if the internal network is compromised. Because the vulnerabilities rely on network access, the primary threat vector is an attacker who has already breached the vessel's local network or has physical access to the hardware.
Since the product is end-of-life, traditional remediation through patching is impossible. The risk remains constant for any vessel still operating this hardware unless network architecture changes.
Defender guidance
To mitigate the risk of unauthorized configuration changes, implement the following measures:
- Network Isolation: Do not connect the FA-50 device directly to the internet.
- Access Control: Ensure the vessel is properly locked and managed to prevent unauthorized physical or local network access.
- Hardware Migration: Transition to the FA-70 successor product, which is not affected by these vulnerabilities.
