Weakness in Watchfire Controller Software Allows Unauthorized Access
CVE-2026-5846

7.6HIGH

Key Information:

Vendor

Watchfire

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-5846?

The Watchfire Controller Software is susceptible to a vulnerability stemming from the usage of hard-coded self-signed RSA private keys and X.509 certificates. These cryptographic elements are employed for authenticating and securing HTTPS/TLS connections to the software’s web management interface. The embedded keys, stored in plaintext within application binaries, pose a significant risk as they may allow unauthorized access to sensitive operations, potentially compromising system integrity and security.

Affected Version(s)

BC550 12.30

BC750 11.33

BC750 12.35

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

James Tilson reported the vulnerability to CISA
.