Junglewise Threat Intelligence

CVE-2026-34021: Wertheim SafeController 5400 lack of cryptographic protection in RS-485 communication

CVE-2026-34021 · Severity: info · CVSS 8.6 · Published 2026-06-15

Vendors: Wertheim.

Executive brief

The Wertheim SafeController 5400, used to manage secure locker systems and vault rooms, contains a vulnerability in how its internal components communicate. Because the communication between the central server and the safe's hardware is not encrypted, an attacker with physical or network access to the wiring can intercept and mimic commands. This could allow an unauthorized person to silence or deactivate safe alarms, potentially facilitating a physical theft without detection.

Technical details

The Wertheim SafeController 5400 (AssemblyVersion 6.11.8130.22320) lacks cryptographic protection on the RS-485 serial communication path between the server and the microcontroller. An attacker with access to the communication medium (adjacent access) can perform a packet-sniffing attack to capture legitimate traffic. By replaying specific captured messages, such as the 'quit alarm' command, the attacker can spoof the server's identity to the microcontroller and continuously deactivate the safe's alarm system. The vendor has stated that no patch will be provided as the hardware is considered End-of-Life (EOL).

Affected products

  • Wertheim SafeController 5400 AssemblyVersion 6.11.8130.22320

Timeline

  • 2023-04-03: other: Vulnerability discovered by SEC Consult
  • 2023-06-20: other: Initial meeting between SEC Consult and Wertheim
  • 2024-03-29: other: Recheck conducted; vulnerability confirmed as not fixed
  • 2024-10-10: other: Vendor confirms no fix will be provided due to EOL status and hardware limitations
  • 2026-06-15: advisory: Public disclosure of vulnerability

References