CVE-2026-5846
MEDIUMHard-coded Cryptographic Key in Watchfire Signs Controllers
Title source: cnaDescription
The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.
Scores
CVSS v3
5.7
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
Details
CWE
CWE-321
Status
published
Products (12)
Watchfire/BC550
12.30
Watchfire/BC550
12.31 SP1
Watchfire/BC750
11.33
Watchfire/BC750
11.34
Watchfire/BC750
12.35
Watchfire/BC750
12.36 SP1
Watchfire/BC760
12.38
Watchfire/BC760
12.41 SP1
Watchfire/BC760
13.00
Watchfire/BC760
14.00 SP1
... and 2 more
Published
Jul 30, 2026
Tracked Since
Jul 31, 2026