FURUNO FA-50 Class B AIS Transponder

Plan PatchCVSS 9.1ICS-CERT ICSA-26-237-07Aug 25, 2026
Energy
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

FURUNO FA-50 Class B AIS Transponder contains vulnerabilities (CWE-798 hardcoded credentials, CWE-306 missing authentication) that allow an attacker to alter device settings without authentication. All versions are affected. The product reached end-of-life in October 2020; FURUNO will not release software updates.

What this means
What could happen
An attacker could alter AIS transponder settings on your vessel or offshore asset, potentially disabling or spoofing maritime position and identification broadcast. This could affect navigation safety, collision avoidance, and regulatory compliance for vessel tracking.
Who's at risk
Energy sector operators, marine/offshore facilities, and vessel operators who use FURUNO FA-50 Class B AIS transponders for maritime navigation, collision avoidance, and vessel identification. This affects any vessel or platform equipped with this end-of-life transponder model.
How it could be exploited
An attacker with network access to the FA-50 transponder (via internet connection or local network) could send commands to change device settings without authentication. The attacker could modify the transponder's transmitted AIS data, disable broadcasts, or reconfigure its behavior.
Prerequisites
  • Network access to the FA-50 transponder
  • No authentication credentials required
remotely exploitableno authentication requiredlow complexityno patch availableend-of-life product
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (1)
ProductAffected VersionsFix Status
FURUNO FA-50 Class B AIS TransponderAll versionsNo fix yet
Remediation & Mitigation
0/4
Do now
0/3
HARDENINGDo not connect the FA-50 AIS transponder directly to the internet
HARDENINGRestrict network access to the FA-50 to only authorized vessel networks; use firewalls or air-gap isolation if possible
HARDENINGImplement physical security controls to prevent unauthorized access to the device and vessel network connections
Long-term hardening
0/1
HARDENINGPlan replacement of the FA-50 with a current, supported AIS transponder model
API: /api/v1/advisories/a004897b-e1e7-4505-aae4-b91d9de8b67e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

FURUNO FA-50 Class B AIS Transponder | CVSS 9.1 - OTPulse