CVE-2026-5846

Summary

The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.

Affected Software

VendorProductVersion RangeStatus
WatchfireBC55012.30affected
WatchfireBC55012.31 SP1unaffected
WatchfireBC75011.33affected
WatchfireBC75011.34unaffected
WatchfireBC75012.35affected
WatchfireBC75012.36 SP1unaffected
WatchfireBC76012.38affected
WatchfireBC76012.41 SP1unaffected
WatchfireBC76013.00affected
WatchfireBC76014.00 SP1unaffected
WatchfireBC760DC12.39affected
WatchfireBC760DC12.41 SP1unaffected

Weaknesses

  • CWE-321: CWE-321 Use of hard-coded cryptographic key

References