SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-5846

MEDIUM · CVSS 5.7 EPSS 0.16% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Watchfire Controller Software is vulnerable due to the presence of hard-coded RSA private keys and X.509 certificates, which are stored in plaintext within the firmware. This flaw compromises the integrity of HTTPS/TLS connections to the web management interface, potentially allowing unauthorized access or man-in-the-middle attacks. Organizations using this software should prioritize remediation to safeguard their systems against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-5846
Severity
MEDIUM
CVSS
5.7
EPSS
0.16%

Original NVD Description

The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.