The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.
History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Watchfire
Watchfire bc550
Watchfire bc750
Watchfire bc760
Watchfire bc760dc
Vendors & Products Watchfire
Watchfire bc550
Watchfire bc750
Watchfire bc760
Watchfire bc760dc

Fri, 31 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Hard-coded Cryptographic Key in Watchfire Signs Controllers Hard-coded Cryptographic Key in Watchfire Controllers

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Description The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.
Title Hard-coded Cryptographic Key in Watchfire Signs Controllers
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2026-07-30T21:12:42.825Z

Updated: 2026-07-31T20:12:49.282Z

Reserved: 2026-04-08T18:55:38.436Z

Link: CVE-2026-5846

cve-icon Vulnrichment

Updated: 2026-07-31T15:31:29.453Z

cve-icon NVD

No data.

cve-icon Redhat

No data.