An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen using that credentials to alter the identification number.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Hard‑coded Credentials Allow Vessel Identification Spoofing |
Tue, 25 Aug 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen using that credentials to alter the identification number. | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2026-08-25T14:51:55.400Z
Reserved: 2026-08-04T01:31:34.626Z
Link: CVE-2026-59769
Updated: 2026-08-25T14:46:33.865Z
Status : Received
Published: 2026-08-25T08:18:09.717
Modified: 2026-08-25T15:16:35.427
Link: CVE-2026-59769
No data.
OpenCVE Enrichment
Updated: 2026-08-25T12:00:07Z
-
CWE-798
Use of Hard-coded Credentials