HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Hard‑Coded Credential Flaw (CVE‑2026‑59769) Lets Network‑Adjacent Attackers Reconfigure FURUNO FA‑50 AIS Transponders

A CISA advisory reports that the FURUNO FA‑50 Class B AIS transponder contains hard‑coded credentials and no authentication for its settings screen (CVE‑2026‑59769, CVSS 9.1). An attacker with access to the vessel’s internal network can alter device settings, exposing maritime operators to operational risk and SOC 2 access‑control gaps.

LiveThreat™ Intelligence · 📅 August 26, 2026· 📰 cisa.gov
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
5 recommended
📰
Source
cisa.gov

Critical Hard‑Coded Credential Vulnerability (CVE‑2026‑59769) in FURUNO FA‑50 AIS Transponder Allows Unauthorized Reconfiguration

What It Is — The FURUNO FA‑50 Class B AIS transponder ships with hard‑coded credentials and lacks authentication for its settings screen. An attacker who can reach the vessel’s internal network can log in with these default credentials and change device configuration.

Exploitability — No public exploit code is required; knowledge of the default credentials is sufficient. The vulnerability carries a CVSS v3 score of 9.1 (Critical).

Affected Products — FURUNO FA‑50 Class B AIS Transponder, all firmware versions (product line discontinued in Oct 2020).

Why It Matters for Compliance & Audit Readiness

  • Access‑Control Gaps – Hard‑coded credentials violate SOC 2 CC6.1 (Logical Access) and CC6.2 (Physical Access) requirements; auditors will expect documented controls and evidence that privileged access is managed.
  • Continuous Monitoring – Legacy OT devices that cannot be patched must be tracked in a control‑monitoring program to demonstrate due diligence and to provide audit‑ready evidence of risk mitigation.
  • Supply‑Chain Due Diligence – Using unsupported third‑party hardware introduces a vendor‑risk exposure that must be reflected in your vendor‑management policies and SOC 2 vendor‑assessment artifacts.

Recommended Actions

  • Network Segmentation – Isolate AIS transponders on a dedicated VLAN with no inbound Internet routes.
  • Credential Hygiene – Disable or change default credentials where possible; document the change as part of your access‑control evidence.
  • Compensating Controls – Deploy intrusion‑detection monitoring on the vessel network to alert on any configuration changes to the transponder.
  • Asset Lifecycle Management – Replace the discontinued FA‑50 units with supported, securely‑designed AIS equipment and update your vendor‑risk register.
  • SOC 2 Evidence – Capture configuration‑change logs and network‑segmentation diagrams as continuous audit evidence for CC6.1/CC6.2.

Source: CISA Advisory – ICSA‑26‑237‑07

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-07

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →