CVE-2026-5846
Received Received - Intake

Hard-Coded RSA Keys in Watchfire Controller Software

Vulnerability report for CVE-2026-5846, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: ICS-CERT

Description

The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
watchfire controller_software *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Watchfire Controller Software uses hard-coded RSA private keys and X.509 certificates embedded in plaintext within application patch binaries. These keys authenticate and encrypt HTTPS/TLS connections to the controller's web management interface. The issue is that these keys are self-signed and hard-coded, making them vulnerable to misuse or extraction by attackers.

Impact Analysis

An attacker could extract the hard-coded keys to decrypt intercepted HTTPS traffic, impersonate the controller, or gain unauthorized access to the web management interface. This could lead to data breaches, unauthorized system control, or further network compromise.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and encryption standards. GDPR and HIPAA mandate strong encryption and secure key management. Hard-coded keys and weak authentication could result in non-compliance, potential fines, and legal consequences.

Mitigation Strategies

Replace the hard-coded RSA private keys and X.509 certificates with new, unique keys and certificates. Ensure all firmware and application binaries are updated to remove embedded plaintext keys. Restrict access to the controller's web management interface and monitor for unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-5846. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart