Government Advisory

Critical Flaw Found in FURUNO Marine AIS Transponder Could Let Attackers Change Device Settings

CISA · 25 Aug 2026
Key Takeaway If your business uses connected operational technology like AIS transponders, regularly check vendor and CISA advisories, and restrict network exposure of these devices wherever possible.

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory for the FURUNO FA-50 Class B AIS Transponder, a marine tracking device used worldwide in the transportation sector. The advisory identifies two serious weaknesses: the use of hard-coded credentials and missing authentication for critical functions, rated with a high CVSS score of 9.1.

These vulnerabilities affect all versions of the device and could allow an attacker to alter its settings without proper authorisation. Because AIS transponders are used to track vessel location and movement, unauthorised changes could impact safety and operational reliability in maritime transport, a sector considered critical infrastructure.

While this device is primarily used in maritime and transportation settings, the advisory is a reminder for all businesses relying on connected operational technology (OT) devices to review vendor security advisories regularly and ensure devices are not exposed to unnecessary network access. Organisations using FURUNO equipment should consult the official CISA advisory and FURUNO's guidance for mitigation steps.

ICS Security CISA Advisory Maritime Technology Hardware Vulnerability OT Security

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.