CVE-2026-5846
Hard-coded Cryptographic Key in Watchfire Signs Controllers
CVSS Score
5.7
EPSS Score
0.0%
EPSS Percentile
0th
The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.
| CWE | CWE-321 |
| Vendor | watchfire |
| Product | bc550 |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for watchfire bc550
Be the first to know when new medium vulnerabilities affecting watchfire bc550 are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
Watchfire / BC550
12.30
Watchfire / BC750
11.33 12.35
Watchfire / BC760
12.38 13.00
Watchfire / BC760DC
12.39
References
Credits
James Tilson reported the vulnerability to CISA