Executive Summary
Critical vulnerabilities CVE-2026-59769 and CVE-2026-67578 were discovered in FURUNO FA-50 Class B AIS Transponder devices used worldwide in maritime transportation systems. The flaws include hardcoded credentials and missing authentication for critical functions, allowing attackers with network access to alter device settings and configurations. With CVSS scores of 9.1 and 7.5 respectively, these vulnerabilities affect all versions of the discontinued product, leaving thousands of vessels potentially exposed to navigation system manipulation. FURUNO ended production in October 2020 and will not provide security updates, recommending only physical security measures and network isolation as mitigations.
This incident highlights the growing risks of legacy IoT/OT devices in critical infrastructure, where end-of-life products continue operating without security support, creating persistent attack vectors that threaten maritime safety and operational integrity.
Why This Matters Now
Maritime cybersecurity is under increased scrutiny as nation-state actors target transportation infrastructure, and legacy IoT devices with hardcoded credentials represent persistent, unpatched attack vectors in critical systems that cannot be easily replaced or updated.
Attack Path Analysis
Attackers exploited hardcoded credentials (CVE-2026-59769) and missing authentication (CVE-2026-67578) in FURUNO FA-50 AIS transponders to gain initial access to maritime vessel networks. From this foothold, they could escalate privileges through the compromised OT device, move laterally across vessel networks, establish command and control channels, exfiltrate sensitive maritime operational data, and potentially disrupt critical navigation and safety systems.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers leveraged hardcoded credentials (CVE-2026-59769) and unauthenticated management interfaces (CVE-2026-67578) to gain access to FURUNO FA-50 AIS transponders connected to vessel networks
Related CVEs
CVE-2026-59769
CVSS 9.1Use of hard-coded credentials in FURUNO FA-50 Class B AIS Transponder allows authenticated attackers with network access to alter device settings.
Affected Products:
FURUNO ELECTRIC CO.,LTD. FA-50 Class B AIS Transponder – all versions
Exploit Status:
no public exploitCVE-2026-67578
CVSS 7.5Missing authentication for critical function in FURUNO FA-50 Class B AIS Transponder allows unauthenticated configuration changes via management screen.
Affected Products:
FURUNO ELECTRIC CO.,LTD. FA-50 Class B AIS Transponder – all versions
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Valid Accounts
Credentials In Files
External Remote Services
Disable or Modify Tools
Account Manipulation
Remote Services
Service Stop
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
PCI DSS 4.0 – Strong Cryptography for Authentication
Control ID: 8.2.1
CISA ZTMM 2.0 – Asset Management and Authentication
Control ID: Identity.AM-1
NIS2 Directive – Access Control Measures
Control ID: Article 21.2(a)
DORA – ICT Risk Management Framework
Control ID: Article 8.1
ISO 27001:2022 – Privileged Access Management
Control ID: A.9.4.3
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Maritime
Critical vulnerability in FURUNO FA-50 AIS transponders affects vessel navigation safety through hardcoded credentials and missing authentication enabling unauthorized device configuration changes.
Transportation
IoT/OT device vulnerabilities in Class B AIS transponders compromise transportation systems security, requiring enhanced network segmentation and encrypted traffic monitoring capabilities.
Logistics/Procurement
Maritime logistics operations face disruption risks from compromised AIS transponder systems, necessitating zero trust segmentation and egress security policy enforcement measures.
Defense/Space
Naval and maritime defense operations vulnerable to AIS transponder exploitation requiring multicloud visibility controls and threat detection systems for critical infrastructure protection.
Sources
- FURUNO FA-50 Class B AIS Transponderhttps://www.cisa.gov/news-events/ics-advisories/icsa-26-237-07Verified
- CVE-2026-59769 Detail - NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-59769Verified
- CVE-2026-67578 Detail - NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-67578Verified
- FURUNO Electric Security Advisoryhttps://www.furuno.com/en/support/securityVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would limit attacker progression through maritime vessel networks by constraining lateral movement between OT systems and reducing the blast radius from compromised AIS transponders. Segmentation controls would likely contain the scope of network access and restrict unauthorized data exfiltration pathways.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial device compromise may still occur, but subsequent network access from the compromised AIS transponder would likely be constrained through identity-aware routing and workload isolation controls
Control: Zero Trust Segmentation
Mitigation: Privilege escalation attempts from the compromised device would likely be constrained to the immediate network segment, reducing the scope of accessible maritime operational systems and administrative functions
Control: East-West Traffic Security
Mitigation: Lateral movement between maritime operational systems would likely be significantly restricted, limiting attacker access to critical navigation, engine management, and communication systems across vessel networks
Control: Multicloud Visibility & Control
Mitigation: Command and control channel establishment would likely be constrained through visibility into satellite and cellular communication patterns, limiting sustained attacker presence across vessel network segments
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration scope would likely be reduced through controlled egress pathways, limiting the volume and types of maritime operational data that could be transmitted to external destinations
While some AIS transponder manipulation may persist, the scope of impact would likely be constrained to the initially compromised device rather than cascading across critical navigation and safety systems
Impact at a Glance
Affected Business Functions
- Maritime Navigation Systems
- Vessel Traffic Management
- AIS Transponder Operations
- Maritime Communication Systems
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of vessel identification data, navigation parameters, and AIS configuration settings through unauthorized device access
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation to isolate maritime OT devices like AIS transponders from broader vessel networks and prevent lateral movement
- • Deploy encrypted traffic controls using MACsec or IPsec to protect sensitive maritime operational data in transit between vessel systems
- • Establish egress security policies to prevent unauthorized data exfiltration from maritime networks and detect anomalous outbound communications
- • Implement multicloud visibility and control capabilities to monitor maritime network traffic and detect suspicious device behavior or configuration changes
- • Deploy threat detection and anomaly response systems to baseline normal AIS transponder behavior and alert on unauthorized configuration modifications or unusual network activity



