CISA

Wärtsilä FOS-Onboard

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client.

The following versions of Wärtsilä FOS-Onboard are affected:

FOS-Onboard 5.07.0923.01 (CVE-2026-78225, CVE-2026-81855)

Vendor

Equipment

Wärtsilä

Wärtsilä FOS-Onboard

Use of Hard-coded Cryptographic Key

Critical Infrastructure Sectors: Transportation Systems

Countries/Areas Deployed: Worldwide

Company Headquarters Location: Finland

A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.

Wärtsilä FOS-Onboard

MitigationWärtsilä states that the vulnerabilities are not exploitable when the product is installed as recommended, and has developed a security patch. Users are also directed to contact Wärtsilä ...