The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-30 22:16
Updated : 2026-09-08 19:30
NVD link : CVE-2026-5846
Mitre link : CVE-2026-5846
CVE.ORG link : CVE-2026-5846
JSON object : View
Products Affected
No product.
CWE
CWE-321
Use of Hard-coded Cryptographic Key
