FURUNO FA-50 AIS Transponder Has Critical Flaws, No Patch Coming
Production ended five years ago, so vessel operators are left with network isolation and locked doors, there is no software fix.
TL;DR
CISA published an advisory Tuesday for FURUNO FA-50 Class B AIS transponders, disclosing hard-coded credentials (CVE-2026-59769, CVSS 9.1) and a missing-authentication flaw (CVE-2026-67578, CVSS 7.5) affecting all firmware versions. Both allow networked attackers to alter device settings, potentially spoofing AIS location data or disrupting traffic management. FURUNO ended production in October 2020 and won't issue patches. Operators still running these units are left with network isolation and physical access control as their only defenses.
The hard-coded credentials vulnerability means anyone who knows them and can reach the in-vessel network gets access to the FA-50's settings screen. The missing-authentication flaw is worse in practice: some configuration changes don't even require credentials. Together they give a networked attacker the ability to alter AIS transmissions, the maritime equivalent of spoofing a transponder on an aircraft.
That's a serious problem with no software fix. FURUNO ended FA-50 production nearly five years ago and has made clear there will be no firmware updates. The company's mitigation guidance amounts to "don't connect it to the internet" and "lock the vessel." Reasonable advice for a device that was never designed for internet exposure, but in modern port and fleet operations, air-gapping an AIS transponder isn't always straightforward.
The FA-50 advisory is the kind of legacy-OT story that repeats across industrial sectors: hardware outlasts vendor support by a decade or more, and the security model assumes physical isolation that faded years ago. CISA's advisory doesn't estimate how many FA-50 units remain in active service, but given maritime hardware refresh cycles measured in decades, the number is unlikely to be zero. For vessel operators, the near-term answer is segmentation, treat the FA-50 as untrusted, isolate it from any network that touches operational technology, and start budgeting for a replacement that still gets patches.
Published ·Deep Fathom