CVE-2026-5846 PUBLISHED

Hard-coded Cryptographic Key in Watchfire Signs Controllers

Assigner: icscert
Reserved: 08.04.2026 Published: 30.07.2026 Updated: 31.07.2026

The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.6

Product Status

Vendor Watchfire
Product BC550
Versions Default: unaffected
  • Version 12.30 is affected
  • Version 12.31 SP1 is unaffected
Vendor Watchfire
Product BC750
Versions Default: unaffected
  • Version 11.33 is affected
  • Version 11.34 is unaffected
  • Version 12.35 is affected
  • Version 12.36 SP1 is unaffected
Vendor Watchfire
Product BC760
Versions Default: unaffected
  • Version 12.38 is affected
  • Version 12.41 SP1 is unaffected
  • Version 13.00 is affected
  • Version 14.00 SP1 is unaffected
Vendor Watchfire
Product BC760DC
Versions Default: unaffected
  • Version 12.39 is affected
  • Version 12.41 SP1 is unaffected

Solutions

Watchfire has applied the required security patch to all affected controllers under its management. Watchfire recommends users verify their controller software version and upgrade to one of the approved versions below, if they are not already on an approved patch level.

Watchfire has issued patches to disable the use of the existing certificate as follows: 

  • BC550 12.30: Patch to 12.31 SP1
  • BC750 11.33: Patch to 11.34
  • BC750 12.35: Patch to 12.36 SP1
  • BC760 12.38: Patch to 12.41 SP1
  • BC760 13.00: Patch to 14.00 SP1
  • BC760DC 12.39: Patch to 12.41 SP1

Credits

  • James Tilson reported the vulnerability to CISA finder

References

Problem Types

  • CWE-321 Use of hard-coded cryptographic key CWE