CVE-2026-59769
9.1FURUNO ELECTRIC CO. · FA-50
The FURUNO ELECTRIC CO. FA-50 marine device contains hard-coded credentials that allow unauthorized users to modify identification numbers via the settings screen.
Executive summary
The FURUNO ELECTRIC CO. FA-50 device is vulnerable to unauthorized configuration changes due to the presence of hard-coded credentials.
Vulnerability
This is a hard-coded credentials vulnerability (CWE-798) that allows an attacker with network access to the vessel's internal system to authenticate and alter critical device identification settings without proper authorization.
Business impact
An attacker gaining control of the device settings could manipulate identification data, which poses significant operational risks for marine navigation systems. With a CVSS score of 9.1, this vulnerability presents a high risk of device compromise and potential disruption of critical maritime communication or tracking functions.
Remediation
Immediate Action: Consult the official FURUNO notice for guidance on mitigation, as no specific version patch is listed, and consider restricting network access to the device.
Proactive Monitoring: Monitor the local network for unauthorized access attempts directed at the FA-50 management interface and watch for unexpected changes to device configuration.
Compensating Controls: Isolate the FA-50 device on a restricted VLAN to ensure that only authorized personnel can communicate with the management interface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given that this vulnerability affects all versions and involves hard-coded credentials, users must treat this as a high-priority risk. Immediately restrict network access to the affected hardware and coordinate with the vendor for long-term remediation strategies.