IM
IronMonkey Threat Research
‹ Back to ICS Advisories

FURUNO FA-50 Class B AIS Transponder

CRITICAL
CVSS 9.1
Date 2026-08-25T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow an attacker to alter device settings.

// Vulnerabilities (2)

CVE ID CVSS Score Severity Description
CVE-2026-59769 9.1 critical
An attacker, who knows the credentials and has access to the in-vessel network to which the device is connected to, may operate the settings screen using that credentials to alter the settings of the device.
CVE-2026-67578 7.5 high
Some configurations may be changed on the management screen without authentication.

// Remediations (1)

Mitigation: FURUNO ELECTRIC CO.,LTD. notes that production of this product ended in October 2020, and software u
FURUNO ELECTRIC CO.,LTD. notes that production of this product ended in October 2020, and software updates will no longer be provided. FURUNO recommends users do not connect the product directly to the internet. To prevent unauthorized access, the vessel on which the product is installed should be properly locked and managed.

// References