Junglewise Threat Intelligence

CVE-2026-34022: Wertheim SafeController 65000 weak custom cryptography and hard-coded keys

CVE-2026-34022 · Severity: info · CVSS 7.1 · Published 2026-06-15

Vendors: Wertheim.

Executive brief

Wertheim SafeControllers are hardware components used to manage electronic safe deposit lockers and vault rooms. A security flaw in the communication protocol allows an attacker with physical or network access to the controller's environment to intercept and decrypt sensitive data traffic. This could lead to the exposure of access codes or system commands, potentially compromising the security of the vault management system.

Technical details

The Wertheim SafeController Family 65000 (specifically AssemblyVersion 6.11.8130.22319) suffers from the use of hard-coded cryptographic keys and a weak, custom encryption algorithm (CWE-321). An attacker positioned as an adversary-in-the-middle on the local network or adjacent communication link can intercept and decrypt data traffic. Research indicates that the encryption routine can be broken without prior knowledge of the key, and the key itself can be recovered by analyzing a sufficient volume of intercepted messages. The vendor has stated that this cannot be fixed due to hardware limitations; users are advised to assess business risks and consider migrating to supported hardware.

Affected products

  • Wertheim SafeController Family 65000 AssemblyVersion 6.11.8130.22319
  • Wertheim Controller 65000 AssemblyVersion 6.11.8130.22319

Timeline

  • 2023-04-03: other: Vulnerability discovered by SEC Consult
  • 2023-06-20: disclosed: Initial meeting with vendor
  • 2024-03-29: other: Recheck confirmed vulnerability remains unfixed
  • 2026-06-15: advisory: Public disclosure by SEC Consult

References