Junglewise Threat Intelligence

CVE-2026-78225: Wärtsilä FOS-Onboard hardcoded cryptographic key in Update Controller

CVE-2026-78225 · Severity: critical · CVSS 9 · Published 2026-09-15

Executive brief

Wärtsilä FOS-Onboard is a maritime system management platform used in ships and critical transportation infrastructure worldwide. A hardcoded cryptographic key in the Update Controller component could allow an attacker with network access to the vessel's systems to deliver unauthorized software updates, execute arbitrary code, or impersonate authorized users, potentially compromising vessel operations and safety.

Technical details

The vulnerability is a use of hardcoded cryptographic keys (CWE-321) in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard version 5.07.0923.01. An attacker with adjacent network access (e.g., access to the maritime vessel's network or operational technology network) can exploit this hardcoded server key to intercept, forge, or tamper with update communications. The vulnerability requires high attack complexity and no user interaction. Successful exploitation allows an attacker to deliver unauthorized updates or extract credentials for privilege escalation. A security patch (version 5.08.4052.01) is available from Wärtsilä. The vendor notes the vulnerability is not exploitable when the product is installed as recommended (implying network isolation).

Affected products

  • Wärtsilä FOS-Onboard 5.07.0923.01

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Patch version 5.08.4052.01 available from Wärtsilä FOS download site

References

Related threats