Impact
The FURUNO ELECTRIC Co., Ltd. FA‑50 product line embeds hard‑coded credentials in all releases. An attacker who has internal network access and knows these credentials can authenticatively log into the settings interface and modify the vessel identification number, potentially enabling spoofing, misidentification, and other operational disruptions.
Affected Systems
All versions of the FURUNO ELECTRIC Co., Ltd. FA‑50 system are vulnerable. No specific firmware or software version numbers are indicated, so every edition contains the hard‑coded credentials.
Risk and Exploitability
The vulnerability scored 8.8 on the CVSS scale, denoting high severity. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog. Exploitation requires only that an attacker have internal network connectivity and knowledge of the default credentials; once authenticated, the attacker can change the vessel identification number without further privilege escalation.
OpenCVE Enrichment