CISA

Watchfire Controller Software

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller.

The following versions of Watchfire Controller Software are affected:

BC550 12.30 (CVE-2026-5846)

BC750 11.33|12.35 (CVE-2026-5846)

BC760 12.38|13.00 (CVE-2026-5846)

BC760DC 12.39 (CVE-2026-5846)

Vendor

Equipment

Watchfire

Watchfire Controller Software

Use of Hard-coded Cryptographic Key

Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Healthcare and Public Health, Financial Services

Countries/Areas Deployed: United States, Dominican Republic, Canada, Peru, El Salvador

Company Headquarters Location: United States

The affected product contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS con...