Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller.
The following versions of Watchfire Controller Software are affected:
BC550 12.30 (CVE-2026-5846)
BC750 11.33|12.35 (CVE-2026-5846)
BC760 12.38|13.00 (CVE-2026-5846)
BC760DC 12.39 (CVE-2026-5846)
Vendor
Equipment
Watchfire
Watchfire Controller Software
Use of Hard-coded Cryptographic Key
Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Healthcare and Public Health, Financial Services
Countries/Areas Deployed: United States, Dominican Republic, Canada, Peru, El Salvador
Company Headquarters Location: United States
The affected product contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS con...
Read the full advisory on CISA →