CVE-2026-59769: Critical severity FA-50 vulnerability
FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen using that credentials to alter the identification number.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Operational
Replace the hard-coded credentials in FA-50 across all versions, since FA-50 all versions contain hard-coded credentials.
Event History
Frequently Asked Questions
Who is exposed to this issue?
FA-50 deployments are affected in all versions. Exploitation requires an attacker to have access to the vessel's internal network and to know the hard-coded credentials.
What can an attacker do after exploiting the credentials?
An attacker can access and operate the settings screen, including changing the identification number. The reported impact affects integrity and availability; no confidentiality impact is listed.
Is authentication alone sufficient to prevent exploitation?
No. The affected credentials are hard-coded, so exposure depends on preventing unauthorized access to the vessel's internal network and preventing attackers from obtaining those credentials.