Executive brief
Watchfire Controller Software, used to manage industrial signage and control systems, contains hard-coded security keys that are publicly accessible in firmware updates. An attacker who obtains these keys could impersonate the controller or intercept encrypted communications between the management interface and users. If successfully exploited, this could allow an attacker to deliver malicious firmware and gain full control over the affected hardware.
Technical details
The vulnerability (CWE-321) involves the use of hard-coded cryptographic keys within the Watchfire Controller Software. Specifically, self-signed RSA private keys and corresponding X.509 certificates used for HTTPS/TLS encryption are embedded in plaintext within application patch binaries. An attacker can extract these keys from firmware files available on Watchfire's Remote Support filestore. With these keys, a remote attacker could perform man-in-the-middle (MitM) attacks to decrypt management traffic or potentially sign and deliver malicious firmware updates to gain full administrative control. Watchfire has released patches (e.g., 12.31 SP1, 11.34, 12.36 SP1, 12.41 SP1, 14.00 SP1) to disable the compromised certificates.
Affected products
- Watchfire BC550 12.30
- Watchfire BC750 11.33, 12.35
- Watchfire BC760 12.38, 13.00
- Watchfire BC760DC 12.39
Timeline
- 2026-07-30: advisory: CISA ICSA-26-211-09 published
- 2026-07-30: patched