CVE-2026-59769
Received Received - Intake

Hard-Coded Credentials in FA-50 Aircraft System

Vulnerability report for CVE-2026-59769, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: JPCERT/CC

Description

FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen using that credentials to alter the identification number.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
furuno fa-50 *
furuno fa-70 *
furuno fa-60 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-59769 involves hard-coded credentials in FA-50 systems across all versions. An attacker with knowledge of these credentials and access to the vessel's internal network can exploit them to alter the identification number via the settings screen.

Detection Guidance

Detection requires checking for hard-coded credentials in FA-50 system configurations. Inspect network traffic for unauthorized access to the settings screen using known credentials. Monitor for unusual changes to vessel identification numbers.

Impact Analysis

This vulnerability allows unauthorized individuals to change critical system settings, potentially leading to operational disruptions, misidentification of the vessel, or unauthorized control of system functions. The high CVSS scores indicate significant impact on integrity and availability.

Compliance Impact

The vulnerability allows unauthorized modification of device settings, including identification numbers, which could lead to misidentification of vessels or false data transmission. This may violate regulations requiring accurate vessel identification and data integrity, such as maritime safety standards. However, the provided context does not explicitly link this vulnerability to GDPR or HIPAA compliance.

Mitigation Strategies

Immediately change all default credentials on the FA-50 system. Isolate the vessel's internal network to restrict access. Update firmware if patches are available. Implement strict access controls and monitor for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59769. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart