Critical Hard‑Coded Credential Vulnerability (CVE‑2026‑59769) in FURUNO FA‑50 AIS Transponder Allows Unauthorized Reconfiguration
What It Is — The FURUNO FA‑50 Class B AIS transponder ships with hard‑coded credentials and lacks authentication for its settings screen. An attacker who can reach the vessel’s internal network can log in with these default credentials and change device configuration.
Exploitability — No public exploit code is required; knowledge of the default credentials is sufficient. The vulnerability carries a CVSS v3 score of 9.1 (Critical).
Affected Products — FURUNO FA‑50 Class B AIS Transponder, all firmware versions (product line discontinued in Oct 2020).
Why It Matters for Compliance & Audit Readiness
- Access‑Control Gaps – Hard‑coded credentials violate SOC 2 CC6.1 (Logical Access) and CC6.2 (Physical Access) requirements; auditors will expect documented controls and evidence that privileged access is managed.
- Continuous Monitoring – Legacy OT devices that cannot be patched must be tracked in a control‑monitoring program to demonstrate due diligence and to provide audit‑ready evidence of risk mitigation.
- Supply‑Chain Due Diligence – Using unsupported third‑party hardware introduces a vendor‑risk exposure that must be reflected in your vendor‑management policies and SOC 2 vendor‑assessment artifacts.
Recommended Actions
- Network Segmentation – Isolate AIS transponders on a dedicated VLAN with no inbound Internet routes.
- Credential Hygiene – Disable or change default credentials where possible; document the change as part of your access‑control evidence.
- Compensating Controls – Deploy intrusion‑detection monitoring on the vessel network to alert on any configuration changes to the transponder.
- Asset Lifecycle Management – Replace the discontinued FA‑50 units with supported, securely‑designed AIS equipment and update your vendor‑risk register.
- SOC 2 Evidence – Capture configuration‑change logs and network‑segmentation diagrams as continuous audit evidence for CC6.1/CC6.2.
Source: CISA Advisory – ICSA‑26‑237‑07