Published:2026/08/25 Last Updated:2026/08/25
JVNVU#95422936
FURUNO ELECTRIC FA-50 CLASS B AIS TRANSPONDER uses hard-coded credentials and misses authentication for additional configuration
Overview
FA-50 CLASS B AIS TRANSPONDER provided by FURUNO ELECTRIC CO., LTD. uses hard-coded credentials and misses authentication for additional configuration.
Products Affected
- FA-50 all versions
Description
FA-50 CLASS B AIS TRANSPONDER provided by FURUNO ELECTRIC CO., LTD. contains the following vulnerabilities.
- Use of hard-coded credentials (CWE-798)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.8
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H Base Score 9.1
- CVE-2026-59769
- The CVSS evaluation above assumes that an attacker who knows the credentials and has access to the network to which the device is connected to operates, using that credentials, the settings screen and alter the identification number etc.
- Missing authentication for critical function (CWE-306)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N Base Score 8.7
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Base Score 7.5
- CVE-2026-67578
Impact
- An attacker, who knows the credentials and has access to the in-vessel network to which the device is connected to, may operate the settings screen using that credentials to alter the settings of the device (CVE-2026-59769).
- Moreover, some additional configuration may be changed on the management screen without authentication (CVE-2026-67578).
Solution
Production of this product ended in October 2020, and software updates will no longer be provided. The vendor recommends to the product users the following measures.
Apply the Workaround
- To prevent unauthorized access, the vessel on which the product is installed should be properly locked and managed
- Do not connect the product directly to the internet
The successor product (FA-70) is not affected by these vulnerabilities.
Vendor Status
| Vendor | Link |
| FURUNO ELECTRIC CO., LTD. | Important notice to our customers who use the FURUNO FA-50 CLASS B AIS TRANSPONDER |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Souvik Kandar reported these issues to CISA ICS. At the request of the developer and CISA ICS, JPCERT/CC coordinated with the developer.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-59769 |
|
CVE-2026-67578 |
|
| JVN iPedia |
|