DEV Community

Anoymask
Anoymask

Posted on

FURUNO FA-50: Hard-coded Credentials and Missing Authentication for Certain Settings (CVE-2026-59769 / CVE-2026-67578)

1. Basic Information

  • Article Title: FURUNO ELECTRIC FA-50 CLASS B AIS TRANSPONDER uses hard-coded credentials and misses authentication for additional configuration
  • Source: JVN
  • Publication Date: 2026-08-25
  • Original Article: JVN
  • Related Sources: FURUNO ELECTRIC, CISA ICS Advisory
  • Related Malware, Threat Groups, CVEs, and Products: CVE-2026-59769, CVE-2026-67578, FURUNO FA-50 CLASS B AIS TRANSPONDER, Successor model FA-70
  • Severity: High (All versions are affected and no patches will be provided. However, network access to the vessel's internal network is a prerequisite, and no public exploitation has been confirmed.)

2. Summary

All versions of the FA-50 have an issue with hard-coded credentials and a lack of authentication for certain settings. Depending on the conditions, an attacker who can reach the vessel's internal network can change identification numbers and some settings. Because the product has reached End-of-Life (EOL) and no patches will be provided, the vendor advises physical security management, avoiding direct internet connections, and upgrading to the successor model, the FA-70.

3. Attack Flow

CVE-2026-59769: Hard-coded Credentials

  1. An attacker gains access to the vessel's internal network where they can reach the FA-50.
  2. The attacker learns or obtains the hard-coded credentials of the FA-50.
  3. The attacker uses these credentials to access the configuration screen.
  4. The attacker changes settings such as identification numbers.

CVE-2026-67578: Missing Authentication for Certain Settings

  1. An attacker reaches the management interface of the FA-50 from the internal network.
  2. The attacker accesses certain configuration functions that do not require authentication.
  3. The attacker changes some configuration parameters.

Public information does not show the initial infection vector, the management screen URI, communication protocol details, or specific exploitation steps.

4. Attacker Position and Execution Location

The confirmed prerequisite is that the attacker has access to the vessel's internal network. Physical entry, onboard Wi-Fi, maintenance terminals, or the compromise of other onboard devices are possible access routes, but public advisories do not state them as confirmed initial entry methods.

The actual targets are the network-based configuration screens and settings functions of the FA-50.

5. Visibility for Victims and Administrators

  • Victims / Operations: If identification numbers or certain settings change, it may be visible as a mismatch in configuration values. However, it is not clear from public information which screens or warnings will notify users.
  • Administrators: Management traffic and configuration differences for the FA-50 are the main points to check. Public information does not state what level of audit logs the product keeps.

6. Success and Failure Conditions

Success Conditions

  • The FA-50 (all versions) is in use.
  • An attacker can reach the FA-50 management interface from the internal network.
  • For CVE-2026-59769, the attacker knows the hard-coded credentials.
  • For CVE-2026-67578, the attacker can reach target configuration functions that work without authentication.

Failure Conditions / Risk Mitigation

  • The FA-50 is not in use, or has been removed and replaced with a newer model.
  • The product is not connected directly to the internet, as recommended by the vendor.
  • The vessel is securely locked and managed so unauthorized users cannot reach the internal network.
  • As an additional measure, communication sources to the FA-50 management interface are limited to the minimum necessary.

Restricting management sources is a defensive recommendation and not a direct countermeasure listed in FURUNO's public guidance.

7. What Happens Upon Success

  • CVE-2026-59769: Settings such as identification numbers can be changed. JVN's CVSS 3.1 score is 9.1, with high impact on Integrity and Availability.
  • CVE-2026-67578: Certain configuration parameters can be changed without authentication. JVN's CVSS 3.1 score is 7.5, with high impact on Integrity.

Specific real-world impacts on navigation, safety, collision avoidance, and external monitoring cannot be confirmed from public information and are not stated as facts.

8. Observable Logs

  • Email: Not directly related.
  • Proxy/SWG/DNS: Standard corporate SWG/DNS logs are unlikely to be primary observation points.
  • Endpoint/EDR: We cannot assume that standard EDR is installed on the FA-50 itself. Configuration exports, maintenance records, and device event logs can be supporting evidence, but public documents do not show the specifications of audit features.
  • Identity/IdP: This is not an authentication issue using an external IdP. CVE-2026-59769 uses shared, hard-coded credentials, making user attribution difficult.
  • SaaS/Cloud: Usually not directly related.
  • Network: Network monitoring that captures traffic sources to the FA-50 management interface, internal segment traffic, and new device connections is useful. Specific ports and URIs cannot be determined from public information.

9. Determining Attack Success

  • Attack Attempt Observed (Success Unconfirmed): Contact from an unauthorized source to the FA-50 management interface is confirmed, but there is no proof of configuration changes.
  • Initial Execution Confirmed: An unauthorized configuration change operation is executed, and differences in identification numbers or target parameters are confirmed.

Because this is not a code execution vulnerability, "initial execution" here uses schema terminology, and the reality is the confirmation of unauthorized configuration changes.

10. Investigation Playbook

  • Trigger: Identify FA-50 assets, detect unauthorized management traffic, or find discrepancies in identification and configuration values.
  • Initial Check: Check the model number, installed vessel, network connections, direct internet connection status, and current vs. approved settings.
  • Endpoints: Preserve available device logs, configuration exports, and maintenance/configuration change records. If log features do not exist, record that absence itself.
  • Authentication / Cloud: Because CVE-2026-59769 makes user-based authentication tracking difficult, supplement this with management terminals, network connection sources, and physical access logs.
  • Subsequent Actions: Check maintenance terminals, wireless APs, gateways, and other devices on the same internal network for signs of unauthorized access.
  • Containment: Disconnect any direct internet connection and isolate unauthorized terminals. If configuration differences are found, verify recovery values with the vendor and operations management, and consider upgrading to the FA-70.
  • Decision Categories: Separate mere network reachability from confirmed actual configuration changes.

11. Defense and Detection Ideas

  • Single Event: Communication to the FA-50 management interface from an unapproved source. However, management port specifications must be verified in each environment.
  • Timeline Correlation: Track the sequence of events: connection of a new internal device -> FA-50 management traffic -> configuration difference.
  • Hunting: Audit all locations where the FA-50 is installed, direct internet connections, shared segments, and maintenance routes.
  • Lack of Logs: Since device audit log specifications are not clear from public information, check in advance if configuration ledgers and network-side evidence can be secured.
  • Priority Measures: Prioritize FURUNO's guidance: "Do not connect directly to the internet," "Properly lock and manage the vessel," and "Consider upgrading to the successor FA-70." In addition, limit management interface access origins on the internal network if possible.

12. Facts / Inference / Hypothesis

Facts

  • All versions of the FA-50 are affected.
  • CVE-2026-59769 uses hard-coded credentials, allowing an attacker on the internal network who knows the credentials to change identification numbers and other settings.
  • CVE-2026-67578 lacks authentication for certain settings, allowing an attacker on the internal network to change some configuration parameters.
  • The FA-50 reached End-of-Life in October 2020, and software updates are not provided.
  • FURUNO advises upgrading to the FA-70, locking and managing vessels, and avoiding direct internet connections.
  • CISA has not confirmed public exploitation.

Inference

  • Since there are no patched versions, asset upgrades and network/physical access controls are the main practical countermeasures.
  • In environments lacking device-side auditing capabilities, network logs and configuration baselines become the core of compromise confirmation.

Hypothesis

  • The specific impact of configuration tampering on operations or external monitoring cannot be determined from public information, and safety impacts should not be assumed without evidence.

13. MITRE ATT&CK Mapping

Because this advisory highlights vulnerability conditions and potential impacts rather than a confirmed attack campaign, MITRE ATT&CK tactics and techniques are not forcibly assigned. Hard-coded credentials should not be mechanically mapped to Default Credentials, nor should attacker TTPs be determined solely based on the possibility of configuration changes.

14. Unknowns and Additional Investigation

The exact values and acquisition methods of the hard-coded credentials, all items modifiable via CVE-2026-67578, specific management communication protocols, URIs and ports, device audit log specifications, and real-world exploitation examples cannot be confirmed from public information.

15. Impact on SOCs and General Organizations

As marine equipment, organizations operating in maritime shipping, ports, fisheries, government agencies, and vessel ownership should prioritize asset discovery for the FA-50. Rather than relying on standard IT EDR solutions, organizations need to manage risks by combining vessel installation records, network reachability, physical security, configuration inventories, and upgrade plans.

16. Summary by Target Audience

  • For SOCs: Identify FA-50 installation sites and management paths. Focus on management traffic and configuration differences observable from the network side. Do not turn unpublicized ports or log specifications into IOCs based on guesswork.
  • For Administrators: Do not connect directly to the internet, properly lock and manage vessels, and consider upgrading to the FA-70. Limit access origins to the management interface if possible.
  • For Users: Crew and maintenance personnel should not connect unauthorized terminals to the internal network, and must report any abnormalities in identification numbers or settings to operations and maintenance managers.

Top comments (0)