CVE-2026-81855 PUBLISHED

Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key

Assigner: icscert
Reserved: 08.09.2026 Published: 15.09.2026 Updated: 16.09.2026

A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Wärtsilä
Product FOS-Onboard
Versions Default: unaffected
  • Version 5.07.0923.01 is affected

Solutions

Wärtsilä states that the vulnerabilities are not exploitable when the product is installed as recommended, and has developed a security patch. Users are also directed to contact Wärtsilä to obtain and install the patch. To obtain and install the latest patch, contact Wärtsilä:  https://www.wartsila.com/services-catalogue/engine-services-4-stroke/wartsila-ics-patch-deployment#contact

Credits

  • Cydome Security Ltd reported this vulnerability to Wärtsilä and CISA. finder

References

Problem Types

  • CWE-321 CWE