CISA Warns of Critical Hard-Coded Credential Vulnerabilities in FURUNO FA-50 Class B AIS Transponder
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an Industrial Control Systems advisory warning of two vulnerabilities affecting the FURUNO FA-50 Class B Automatic Identification System (AIS) Transponder. The device, which ended production in October 2020, is affected by CVE-2026-59769 and CVE-2026-67578. CVE-2026-59769, rated CRITICAL with a CVSS v3.1 score of 9.1, involves the use of hard-coded credentials that could allow an attacker with network access to alter device settings. CVE-2026-67578, rated HIGH with a CVSS v3.1 score of 7.5, involves missing authentication for critical functions on the management screen. No known public exploitation has been reported, but the end-of-life status of the product means remaining deployed units face persistent risk without future software updates from the vendor.