Executive brief
Gallagher Controller 6000 and 7000 devices, which manage physical access control and security systems, contain a vulnerability in their diagnostic web interface. An authorized user with high-level permissions could intentionally or accidentally cause the controller to restart by sending specific web requests. This results in a temporary service outage where security functions managed by the controller may be unavailable until the device finishes rebooting.
Technical details
A vulnerability classified as an Uncaught Exception (CWE-248) exists within the diagnostic web interface of Gallagher Controller 6000 and 7000 hardware. An authenticated and authorized operator can trigger this exception by sending specifically crafted requests to the diagnostic interface, leading to a software crash and subsequent controller restart. This results in a temporary denial of service (DoS). The attack requires network access to the diagnostic interface and high privileges (PR:H). Gallagher recommends disabling the diagnostic web interface via physical DIP switches or software configuration as a primary mitigation. Patches are available in Command Centre maintenance releases for versions 9.20 through 9.50.
Affected products
- Gallagher Controller 6000 Command Centre 9.50 prior to vCR9.50.260616a, 9.40 prior to vCR9.40.260616a, 9.30 prior to vCR9.30.260616a, 9.20 prior to vCR9.20.260616a, and all versions 9.10 and prior
- Gallagher Controller 7000 Command Centre 9.50 prior to vCR9.50.260616a, 9.40 prior to vCR9.40.260616a, 9.30 prior to vCR9.30.260616a, 9.20 prior to vCR9.20.260616a, and all versions 9.10 and prior
Timeline
- 2026-07-07: advisory
- 2026-07-07: disclosed