# Furuno FA-50 AIS Transponder Has Two Flaws

Published: 2026-08-25 · Severity: routine · Sectors: transportation
Canonical: https://vorant.io/reports/e1ff62bc-347e-5d90-8f82-4a22667afcb5/furuno-fa-50-ais-transponder-has-two-flaws

> CISA advisory details hard-coded credentials and missing authentication in end-of-life Furuno FA-50 AIS transponders used on vessels worldwide.

CISA published an advisory for the FURUNO FA-50 Class B AIS Transponder, a marine automatic identification system device deployed worldwide and manufactured by Japan-based Furuno Electric. Two vulnerabilities are disclosed: CVE-2026-59769, involving hard-coded credentials (CWE-798) that could allow someone with network access and knowledge of the credentials to alter device settings; and CVE-2026-67578, a missing authentication for critical function flaw (CWE-306) that could allow configuration changes on the management screen without any authentication at all.

The product reached end-of-life in October 2020 and will not receive software updates, so remediation relies entirely on compensating controls. Furuno and CISA recommend not connecting the device directly to the internet, physically securing vessels to prevent unauthorized access to the in-vessel network, and standard ICS network segmentation practices (isolating control system networks behind firewalls, using VPNs for remote access where required). No public exploitation of these vulnerabilities has been reported to CISA at this time.

This is a low-complexity, physical/network-adjacent access issue affecting transportation-sector (maritime) equipment. Given the device is unpatchable and requires either credential knowledge or in-vessel network access to exploit, and there is no known active exploitation, the practical urgency is limited to affected vessel operators who should verify network isolation and physical security controls.

## Mentioned in this report

- Vulnerabilities: CVE-2026-59769, CVE-2026-67578

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-07

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e1ff62bc-347e-5d90-8f82-4a22667afcb5/furuno-fa-50-ais-transponder-has-two-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
