Weakness in Watchfire Controller Software Allows Unauthorized Access
CVE-2026-5846
7.6HIGH
What is CVE-2026-5846?
The Watchfire Controller Software is susceptible to a vulnerability stemming from the usage of hard-coded self-signed RSA private keys and X.509 certificates. These cryptographic elements are employed for authenticating and securing HTTPS/TLS connections to the software’s web management interface. The embedded keys, stored in plaintext within application binaries, pose a significant risk as they may allow unauthorized access to sensitive operations, potentially compromising system integrity and security.
Affected Version(s)
BC550 12.30
BC750 11.33
BC750 12.35
References
CVSS V4
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
James Tilson reported the vulnerability to CISA
