Security & Threat Intelligence · 30.07.2026, 17:34 UTC
Watchfire Controller Software
| Schweregrad | info |
|---|---|
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA Advisories ↗ |
| Veröffentlicht | 30.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-5846. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller. The following versions of Watchfire Controller Software are affected:
BC550 12.30 (CVE-2026-5846) BC750 11.33|12.35 (CVE-2026-5846) BC760 12.38|13.00 (CVE-2026-5846) BC760DC 12.39 (CVE-2026-5846)
CVSS Vendor Equipment Vulnerabilities
v3 5.7 Watchfire Watchfire Controller Software Use of Hard-coded Cryptographic Key
Background
Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Healthcare and Public Health, Financial Services Countries/Areas Deployed: United States, Dominican Republic, Canada, Peru, El Salvador Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-5846
The affected product contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore. View CVE Details
Affected Products Watchfire Controller Software
Vendor:Watchfire Product Version:Watchfire BC550: 12.30, Watchfire BC750: 11.33|12.35, Watchfire BC760: 12.38|13.00, Watchfire BC760DC: 12.39 Product Status:known_affected
Remediations MitigationWatchfire has applied the required security patch to all affected controllers under its management. Watchfire recommends users verify …