CVE Feed

    Dashboard / CVE / CVE-2026-5846

    CVE-2026-5846

    The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.

    Published:Jul 30, 2026
    Last Modified:Aug 2, 2026
    EPS:Jul 30, 2026
    EPSS Score:0.00163
    CVSS Score:5.7

    Affected Products

    Vendor
    Watchfire
    Product
    Bc550
    Vendor
    Watchfire
    Product
    Bc750
    Vendor
    Watchfire
    Product
    Bc760
    Vendor
    Watchfire
    Product
    Bc760dc

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High