Description
A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.
Published: 2026-09-15
Score: 9.5 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality Compromise
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a fixed cryptographic server key embedded within the deployer‑ng Update Controller component of Wärtsilä FOS‑Onboard. This key can be used by an attacker to decrypt secured traffic, sign certificates, or forge control commands, thereby compromising the confidentiality and integrity of all data the Update Controller protects. The flaw is a key‑management weakness, classified as CWE‑321, and because the key is immutable, exploitation provides persistent backdoor access to the system’s control plane.

Affected Systems

The issue affects Wärtsilä FOS‑Onboard deployments that include the deployer‑ng Update Controller. No specific version numbers are indicated in the available data, so all instances of FOS‑Onboard that contain the affected component may be vulnerable until the vendor‑issued patch is applied. Administrators should verify that their installations meet Wärtsilä’s recommended configuration guidance.

Risk and Exploitability

The CVSS score of 9.5 indicates a high‑severity flaw, but the EPSS score of less than 1% suggests that, at present, exploitation is unlikely. The vulnerability is not listed in CISA’s KEV catalog, implying no confirmed attacks yet. Based on the description, it is inferred that the attack vector would involve an attacker gaining network or administrative access to the Update Controller to inject malicious update packages or otherwise interact with the hard‑coded key, allowing decryption of traffic and creation of forged messages.

Generated by OpenCVE AI on September 18, 2026 at 14:10 UTC.

Remediation

Vendor Solution

Wärtsilä states that the vulnerabilities are not exploitable when the product is installed as recommended and has developed a security patch. The patch (version 5.08.4052.01) can be found on the Wärtsilä FOS download site https://www.wartsila.com/marine/products/data-service-downloads/fos-downloads . Users can also contact Wärtsilä https://www.wartsila.com/services-catalogue/engine-services-4-stroke/wartsila-ics-patch-deployment#contact to obtain and install the patch.


OpenCVE Recommended Actions

  • Obtain and install the vendor security patch from Wärtsilä for the deployer‑ng Update Controller component.
  • Configure FOS‑Onboard according to Wärtsilä’s recommended deployment guidance, which includes disabling legacy update paths that expose the hard‑coded key.
  • Segregate the Update Controller traffic with network segmentation and firewall rules to restrict its exposure to trusted management networks.

Generated by OpenCVE AI on September 18, 2026 at 14:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 22:30:00 +0000


Thu, 24 Sep 2026 21:45:00 +0000


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Wärtsilä
Wärtsilä fos-onboard
Vendors & Products Wärtsilä
Wärtsilä fos-onboard

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.
Title Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Wärtsilä Fos-onboard
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-24T21:37:04.294Z

Reserved: 2026-09-08T16:53:35.715Z

Link: CVE-2026-78225

cve-icon Vulnrichment

Updated: 2026-09-16T18:05:12.653Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T22:17:02.870

Modified: 2026-09-24T22:17:01.720

Link: CVE-2026-78225

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:15:09Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key