Executive brief
The Furuno FA-50 is a Class B AIS transponder used by vessels to broadcast identification and navigation data. The device contains hard-coded credentials and lacks authentication controls, allowing an attacker with network access to the vessel's internal system to modify critical settings such as the ship's identification number and other device configurations. This could lead to vessel misidentification, spoofing, or disruption of maritime operations.
Technical details
The FA-50 contains two vulnerabilities: (1) hard-coded credentials (CWE-798) that allow any attacker who knows them to access the settings screen, and (2) missing authentication for critical configuration functions (CWE-306). Both require network access to the vessel's internal network but do not require authentication or user interaction beyond knowing the static credentials. An attacker can alter device identification numbers and other operational parameters, compromising vessel identity and navigation integrity. Production ended in October 2020 with no software updates available; the vendor recommends upgrading to the successor model FA-70 or implementing network isolation measures.
Affected products
- Furuno Electric FA-50 Class B AIS Transponder all versions
Timeline
- 2026-08-25: disclosed