CISA has issued an alert regarding two critical vulnerabilities (CVE-2026-59769 and CVE-2026-67578) in the FURUNO FA-50 maritime transponder, which allow remote unauthorized access to modify device settings. The vulnerabilities are categorized with a severity score of 9.1 and 7.5, respectively, and affect all versions of the FA-50. The main issues include hard-coded credentials and a missing authentication check. Importantly, no software patches will be released by the vendor.
Consequently, administrators are advised to enhance physical and network security and avoid direct internet connections to the transponder, as compromising this system poses serious risks to maritime operations.