Published:2026/08/25  Last Updated:2026/08/25

JVNVU#95422936
FURUNO ELECTRIC FA-50 CLASS B AIS TRANSPONDER uses hard-coded credentials and misses authentication for additional configuration

Overview

FA-50 CLASS B AIS TRANSPONDER provided by FURUNO ELECTRIC CO., LTD. uses hard-coded credentials and misses authentication for additional configuration.

Products Affected

  • FA-50 all versions

Description

FA-50 CLASS B AIS TRANSPONDER provided by FURUNO ELECTRIC CO., LTD. contains the following vulnerabilities.

  • Use of hard-coded credentials (CWE-798)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.8
    • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H Base Score 9.1
    • CVE-2026-59769
    • The CVSS evaluation above assumes that an attacker who knows the credentials and has access to the network to which the device is connected to operates, using that credentials, the settings screen and alter the identification number etc.
  • Missing authentication for critical function (CWE-306)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N Base Score 8.7
    • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Base Score 7.5
    • CVE-2026-67578

Impact

  • An attacker, who knows the credentials and has access to the in-vessel network to which the device is connected to, may operate the settings screen using that credentials to alter the settings of the device (CVE-2026-59769).
  • Moreover, some additional configuration may be changed on the management screen without authentication (CVE-2026-67578).

Solution

Production of this product ended in October 2020, and software updates will no longer be provided. The vendor recommends to the product users the following measures.

Apply the Workaround

  • To prevent unauthorized access, the vessel on which the product is installed should be properly locked and managed
  • Do not connect the product directly to the internet
Switch to the successor product
The successor product (FA-70) is not affected by these vulnerabilities.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Souvik Kandar reported these issues to CISA ICS. At the request of the developer and CISA ICS, JPCERT/CC coordinated with the developer.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-59769
CVE-2026-67578
JVN iPedia