CVE-2026-59769

high

Description

FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen using that credentials to alter the identification number.

References

https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-07

https://www.furuno.co.jp/news/notice/notice_category.html?itemid=1856&dispmid=1039

https://www.furuno.co.jp/en/news/notice/notice_category.html?itemid=1857&dispmid=965

https://jvn.jp/en/vu/JVNVU95422936/

Details

Source: Mitre, NVD

Published: 2026-08-25

Updated: 2026-08-28

Risk Information

CVSS v2

Base Score: 9.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Severity: Critical

CVSS v4

Base Score: 8.8

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00331