Critical Flaw Found in FURUNO Marine AIS Transponder Could Let Attackers Change Device Settings
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory for the FURUNO FA-50 Class B AIS Transponder, a marine tracking device used worldwide in the transportation sector. The advisory identifies two serious weaknesses: the use of hard-coded credentials and missing authentication for critical functions, rated with a high CVSS score of 9.1.
These vulnerabilities affect all versions of the device and could allow an attacker to alter its settings without proper authorisation. Because AIS transponders are used to track vessel location and movement, unauthorised changes could impact safety and operational reliability in maritime transport, a sector considered critical infrastructure.
While this device is primarily used in maritime and transportation settings, the advisory is a reminder for all businesses relying on connected operational technology (OT) devices to review vendor security advisories regularly and ensure devices are not exposed to unnecessary network access. Organisations using FURUNO equipment should consult the official CISA advisory and FURUNO's guidance for mitigation steps.