Our takeCISA flags a CVSS 9.1 flaw in FURUNO FA-50 Class B AIS transponders — all versions — letting an attacker alter device settings. Class B means small vessels: fishing boats, workboats, small operators. If you run one, ask FURUNO about a fix and keep the unit off untrusted networks.Cyber Resilience desk
Sources (1)
- cisa_ics · cisa_ics
What this means for you — Security leader:CISA reports active exploitation in all versions of the FURUNO FA-50 Class B AIS Transponder; successful attacks let an adversary change device settings. Apply the vendor's fixes immediately and segment any AIS gear from production networks.
What this means for you — Lean IT orgs:This marine navigation device has confirmed vulnerabilities that let attackers change its settings. If your team uses a FURUNO FA-50, check the manufacturer's advisory and update it right away.
What this means for you — MSP:All versions of the FURUNO FA-50 Class B AIS Transponder are affected by actively exploited vulnerabilities that allow configuration changes. Review client inventories for these units, apply the vendor patch, and isolate them from other networks.
What this means for you — Researcher:CISA advisory ICSA-26-237-07 confirms active exploitation in every version of the FURUNO FA-50; CVSS 9.1 for improper access control leading to device setting manipulation.