Description
FA-50 all versions contain hard-coded credentials.
An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen using that credentials to alter the identification number.
Published: 2026-08-25
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Authenticated attackers possessing the hard‑coded credentials can alter the vessel identification number
Action: Immediate Patch
AI Analysis

Impact

The FURUNO ELECTRIC Co., Ltd. FA‑50 product line embeds hard‑coded credentials in all releases. An attacker who has internal network access and knows these credentials can authenticatively log into the settings interface and modify the vessel identification number, potentially enabling spoofing, misidentification, and other operational disruptions.

Affected Systems

All versions of the FURUNO ELECTRIC Co., Ltd. FA‑50 system are vulnerable. No specific firmware or software version numbers are indicated, so every edition contains the hard‑coded credentials.

Risk and Exploitability

The vulnerability scored 8.8 on the CVSS scale, denoting high severity. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog. Exploitation requires only that an attacker have internal network connectivity and knowledge of the default credentials; once authenticated, the attacker can change the vessel identification number without further privilege escalation.

Generated by OpenCVE AI on August 25, 2026 at 11:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑supplied firmware or software update that eliminates hard‑coded credentials or implements proper authentication mechanisms.
  • If no update is available, replace the default credentials with unique, strong values and, where possible, disable the default account or restrict its use.
  • Limit physical and network access to the vessel’s internal network and enforce role‑based access controls for configuration changes.

Generated by OpenCVE AI on August 25, 2026 at 11:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Furuno Electric
Furuno Electric fa-50
Vendors & Products Furuno Electric
Furuno Electric fa-50

Tue, 25 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title Hard‑coded Credentials Allow Vessel Identification Spoofing

Tue, 25 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Description FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen using that credentials to alter the identification number.
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Furuno Electric Fa-50
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-25T14:51:55.400Z

Reserved: 2026-08-04T01:31:34.626Z

Link: CVE-2026-59769

cve-icon Vulnrichment

Updated: 2026-08-25T14:46:33.865Z

cve-icon NVD

Status : Deferred

Published: 2026-08-25T08:18:09.717

Modified: 2026-08-28T16:09:10.947

Link: CVE-2026-59769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:38:02Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials