Hardcoded Cryptographic Server Key Vulnerability in Wärtsilä FOS-Onboard Update Controller
CVE-2026-78225

9.5CRITICAL

Key Information:

Vendor

Wärtsilä

Vendor
CVE Published:
15 September 2026

What is CVE-2026-78225?

A hardcoded cryptographic server key vulnerability is present in the Deployer-ng Update Controller component of Wärtsilä FOS-Onboard. This flaw could potentially allow unauthorized access, leading to severe security risks. It's crucial for users to assess their systems and apply necessary updates to mitigate exposure to potential threats stemming from this vulnerability.

Affected Version(s)

FOS-Onboard 5.07.0923.01

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Cydome Security Ltd reported this vulnerability to Wärtsilä and CISA.
.