🔐 CVE Alert

CVE-2026-5846

MEDIUM 5.7

Hard-coded Cryptographic Key in Watchfire Signs Controllers

CVSS Score
5.7
EPSS Score
0.0%
EPSS Percentile
0th

The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.

CWE CWE-321
Vendor watchfire
Product bc550
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for watchfire bc550

Be the first to know when new medium vulnerabilities affecting watchfire bc550 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

Watchfire / BC550
12.30
Watchfire / BC750
11.33 12.35
Watchfire / BC760
12.38 13.00
Watchfire / BC760DC
12.39

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cisa.gov: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-09 github.com: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-09.json

Credits

James Tilson reported the vulnerability to CISA