CVE-2026-67578
7.5FURUNO · FA-50
The FURUNO FA-50 maritime AIS transponder is vulnerable to a missing authentication flaw that allows unauthorized modification of critical configurations.
Executive summary
A critical authentication failure in the FURUNO FA-50 allows unauthorized users to modify device configurations, posing a high risk to operational security.
Vulnerability
The device fails to enforce authentication for certain critical configuration functions (CWE-306). This allows an unauthenticated, network-adjacent attacker to alter device settings.
Business impact
With a CVSS score of 7.5, this high-severity vulnerability allows an attacker to manipulate the configuration of critical maritime equipment. Unauthorized changes could lead to the degradation of AIS services, incorrect data transmission, or potential operational disruption. Given the nature of this hardware, such unauthorized access could have significant safety and regulatory implications.
Remediation
Immediate Action: Consult the official FURUNO notice and contact the vendor or a certified service technician to determine if a firmware update or specific configuration workaround is available.
Proactive Monitoring: Monitor the device's network traffic for unauthorized access attempts and verify current configuration settings against established baselines periodically.
Compensating Controls: Isolate the FA-50 device on a dedicated, firewalled network segment to ensure that only authorized control systems can communicate with it.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This is a critical security issue for maritime infrastructure. Operators must immediately isolate the affected devices from public or untrusted networks and contact FURUNO for guidance on patching or hardening the device configuration to mitigate unauthorized access.