Post

Watchfire Controller Software Vulnerability Alert

Watchfire Controller Software Vulnerability Alert

Watchfire Controller Software Vulnerability Alert 🚨

On July 30, 2026, CISA published an alert regarding a significant vulnerability in the Watchfire Controller Software. This vulnerability, identified as CVE-2026-5846, could allow malicious users to deliver harmful firmware that can gain full control of the controller.

Affected Versions:

  • BC550 12.30
  • BC750 11.3312.35
  • BC760 12.3813.00
  • BC760DC 12.39

These controllers are utilized across various Critical Infrastructure Sectors, including:

  • Commercial Facilities
  • Critical Manufacturing
  • Healthcare and Public Health
  • Financial Services

Vulnerability Details:

The vulnerability arises from the presence of self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller’s web management interface. These keys are embedded in plaintext within the firmware binaries from Watchfire’s Remote Support filestore.

Watchfire has released security patches for all affected controllers. Users are advised to verify their controller software version and upgrade to the approved versions:

  • BC550 12.30: Patch to 12.31 SP1
  • BC750 11.33: Patch to 11.34
  • BC750 12.35: Patch to 12.36 SP1
  • BC760 12.38: Patch to 12.41 SP1
  • BC760 13.00: Patch to 14.00 SP1
  • BC760DC 12.39: Patch to 12.41 SP1

CISA recommends minimizing network exposure for all control system devices and ensuring they are not accessible from the internet. When remote access is necessary, utilize secure methods such as Virtual Private Networks (VPNs).

For further details, please read the complete article: Read full article

This post is licensed under CC BY 4.0 by the author.