CISA alerts hard-coded credential flaw in Furuno FA-50 AIS transponders
All versions of Furuno's FA-50 Class B AIS transponder are vulnerable to CVE-2026-59769 as of the advisory issued 25 August 2026.

The Cybersecurity and Infrastructure Security Agency (CISA) released an advisory on 25 August 2026 identifying a critical vulnerability, CVE-2026-59769, in Furuno Electric Co., Ltd.'s FA-50 Class B AIS transponder. The flaw, rated 9.1 on the CVSS v3 scale, stems from hard-coded credentials and missing authentication for a critical function, allowing an attacker who knows the credentials and has access to the vessel's network to alter the device's settings.
The advisory notes that the FA-50 transponder, deployed worldwide in transportation systems, is classified as critical infrastructure. Exploitation requires only network access to the in-vessel environment and knowledge of the embedded credentials, which are present in all product versions (vers:all/*).
CISA recommends operators minimize network exposure for all control-system devices, isolate them behind firewalls, and keep them separate from business networks. When remote access is necessary, agencies should employ secure methods such as VPNs, ensuring the VPN software is up to date. Organizations are also urged to conduct impact analysis and risk assessments before implementing defensive measures and to follow the control-systems security practices detailed on the CISA ICS webpage, including the technical information paper ICS-TIP-12-146-01B.
No public exploitation of the vulnerability has been reported. The issue was reported by Souvik Kandar and coordinated with JPCERT/CC and Furuno Electric. The advisory is subject to CISA's notification and privacy policies, and organizations observing suspicious activity should follow internal procedures and report findings to CISA for tracking.
Further reading



