CVE-2026-5846 MEDIUM

CVE-2026-5846: Hard-coded Cryptographic Key in Watchfire Signs Controllers

Vendor Watchfire
Product BC550
Weakness CWE-321
Published July 30, 2026
Last update July 31, 2026

CVSS base score

5.7/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.

Key dates

02Disclosure timeline

July 30, 2026 CVE published
July 31, 2026 Record updated