VYPR
advisoryPublished Sep 15, 2026· 1 source

Critical Vulnerabilities in Wärtsilä FOS-Onboard Threaten Maritime Operations

CISA has disclosed two critical vulnerabilities in Wärtsilä FOS-Onboard software, potentially allowing attackers to deliver unauthorized updates, execute code, or steal credentials.

CISA has issued a stern warning regarding critical vulnerabilities affecting Wärtsilä's FOS-Onboard software, a system integral to maritime operations. The advisory highlights two specific flaws, tracked as CVE-2026-78225 and CVE-2026-81855, both stemming from the use of hard-coded cryptographic keys within the software. These vulnerabilities, present in version 5.07.0923.01, carry a critical CVSS v3.1 base score of 9.1 and a CVSS v4.0 score of 9.3, indicating a high potential for severe impact.

The first vulnerability, CVE-2026-78225, resides in the deployer-ng Update Controller component. The presence of a hard-coded cryptographic server key in this component could enable an attacker to bypass security measures and deliver unauthorized software updates to the FOS-Onboard system. This could lead to the installation of malicious code or backdoors, compromising the integrity and functionality of the onboard systems.

Complementing this, CVE-2026-81855 affects the robot testing framework component, also due to a hard-coded cryptographic key, specifically for client authentication. Successful exploitation of this flaw could allow an attacker to impersonate a privileged client, potentially gaining unauthorized access to sensitive system functions, credentials, or operational data. The combination of these two vulnerabilities presents a significant risk, enabling attackers to not only compromise the system's integrity but also to potentially steal sensitive information or gain privileged access.

Wärtsilä has acknowledged these vulnerabilities and states that they are not exploitable when the product is installed according to recommended security practices. However, to address the identified risks, the company has developed a security patch. Users are strongly advised to contact Wärtsilä directly to obtain and install this critical patch. The company provides a dedicated contact point for this purpose through their services catalogue.

These vulnerabilities were reported to Wärtsilä and CISA by Cydome Security Ltd, highlighting the ongoing efforts of security researchers in identifying and mitigating risks within industrial control systems. The FOS-Onboard system is deployed worldwide across the transportation sector, underscoring the global reach of this potential threat.

CISA strongly recommends that organizations take immediate defensive measures to minimize the risk of exploitation. These measures include minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and locating control system networks behind firewalls, isolating them from business networks. Where remote access is necessary, secure methods like VPNs should be employed, with the caveat that VPNs themselves must be kept updated and secure.

While no known public exploitation targeting these specific vulnerabilities has been reported to CISA at this time, the critical nature of the flaws and the potential impact on maritime operations warrant immediate attention. Organizations are encouraged to perform thorough impact analyses and risk assessments before implementing any defensive measures and to follow established procedures for reporting any suspected malicious activity.

The disclosure serves as a critical reminder of the importance of robust security practices within the operational technology (OT) landscape, particularly in critical infrastructure sectors like transportation, where system integrity and availability are paramount.

Synthesized by Vypr AI