Junglewise Threat Intelligence

CVE-2026-67578: FURUNO FA-50 missing authentication in configuration management

CVE-2026-67578 · Severity: high · CVSS 7.5 · Published 2026-08-25

Executive brief

The FURUNO FA-50 is a Class B AIS transponder used on vessels to broadcast identification and positioning information. An attacker with access to a ship's internal network can bypass authentication and alter critical configuration settings including the vessel's identification number without any authorization. Since the product reached end-of-life in October 2020 and no patches are available, affected vessels face ongoing operational and safety risks.

Technical details

The FA-50 contains a missing authentication vulnerability (CWE-306) in its configuration management interface, allowing unauthenticated access to critical functions over the network. An attacker with network access to the vessel's internal network can directly manipulate the settings screen and modify identification parameters and other configuration data without providing credentials. The vulnerability is network-reachable but requires the attacker to be connected to the same vessel network; direct internet exposure compounds the risk. The product reached end-of-life in October 2020 and will receive no software updates; the successor product FA-70 is not affected.

Affected products

  • FURUNO FA-50 all versions

Timeline

  • 2026-08-25: disclosed

References