CVE-2026-5846
5.7
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
Summary
The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Watchfire | BC550 | 12.30 | affected |
| Watchfire | BC550 | 12.31 SP1 | unaffected |
| Watchfire | BC750 | 11.33 | affected |
| Watchfire | BC750 | 11.34 | unaffected |
| Watchfire | BC750 | 12.35 | affected |
| Watchfire | BC750 | 12.36 SP1 | unaffected |
| Watchfire | BC760 | 12.38 | affected |
| Watchfire | BC760 | 12.41 SP1 | unaffected |
| Watchfire | BC760 | 13.00 | affected |
| Watchfire | BC760 | 14.00 SP1 | unaffected |
| Watchfire | BC760DC | 12.39 | affected |
| Watchfire | BC760DC | 12.41 SP1 | unaffected |
Weaknesses
- CWE-321: CWE-321 Use of hard-coded cryptographic key
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-09
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-09.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.