VYPR
advisoryPublished Jul 30, 2026· 1 source

Watchfire Controller Software Vulnerable to Malicious Firmware Delivery

CISA alerts users to a critical vulnerability in Watchfire Controller Software that could allow attackers to deliver malicious firmware and gain full control.

CISA has issued an advisory detailing a critical vulnerability, identified as CVE-2026-5846, affecting multiple versions of Watchfire Controller Software. The flaw stems from the use of hard-coded RSA private keys and certificates within the firmware, which are employed for authenticating and encrypting connections to the controller's web management interface. These keys are embedded in plaintext within the application patch binaries, making them accessible to attackers.

Successful exploitation of this vulnerability could permit a malicious actor to deliver unauthorized firmware updates. This would grant the attacker complete control over the affected controllers, posing a significant risk to industrial control systems. The vulnerability impacts several versions across different Watchfire controller models, including BC550, BC750, BC760, and BC760DC.

The affected product versions include Watchfire BC550 version 12.30, BC750 versions 11.33 and 12.35, BC760 versions 12.38 and 13.00, and BC760DC version 12.39. These systems are deployed across critical infrastructure sectors such as Commercial Facilities, Critical Manufacturing, Healthcare and Public Health, and Financial Services in countries including the United States, Dominican Republic, Canada, Peru, and El Salvador.

Watchfire has acknowledged the vulnerability and has begun patching affected controllers under its management. For users managing their own systems, Watchfire recommends verifying controller software versions and upgrading to specific patched versions. These include upgrading BC550 12.30 to 12.31 SP1, BC750 11.33 to 11.34, BC750 12.35 to 12.36 SP1, BC760 12.38 to 12.41 SP1, BC760 13.00 to 14.00 SP1, and BC760DC 12.39 to 12.41 SP1.

The Common Vulnerability Scoring System (CVSS) v3.1 base score for this vulnerability is 5.7 (MEDIUM), with a CVSS v4.0 score of 7.6 (HIGH). The attack vector is network-based, but requires high privileges and has high attack complexity, with a user interaction requirement. The potential impact includes high confidentiality and integrity loss.

CISA advises organizations to implement defensive measures to minimize the risk of exploitation. These recommendations include minimizing network exposure of control system devices, locating them behind firewalls, and isolating them from business networks. When remote access is necessary, secure methods like VPNs should be utilized, ensuring they are kept up-to-date.

While no public exploitation targeting this specific vulnerability has been reported to CISA at this time, the high attack complexity and potential for significant impact warrant prompt attention. Organizations are encouraged to perform thorough impact analyses and risk assessments before deploying any defensive measures and to follow established procedures for reporting any suspected malicious activity.

This advisory highlights the ongoing risks associated with hard-coded credentials and cryptographic keys in industrial control systems, underscoring the need for regular security audits and timely patching to protect critical infrastructure from potential compromise.

Synthesized by Vypr AI