Hardcoded Cryptographic Keys in Wärtsilä Ship Management Software Rated Critical

Container port protected by maritime and landside security systems

CISA disclosed two critical vulnerabilities in Wärtsilä FOS-Onboard, fleet-management software used aboard vessels, after the flaws were reported by maritime cybersecurity firm Cydome Security. CVE-2026-78225, rated 9.1 to 9.5 depending on scoring version, is a hardcoded cryptographic server key in the software’s Update Controller component that could let an attacker deliver an unauthorized software update or execute code on affected systems.

A second flaw, CVE-2026-81855, is a hardcoded client authentication key in a robot-testing-framework component that could let an attacker extract credentials and impersonate a privileged client. Wärtsilä said the vulnerabilities are not exploitable under its recommended installation configuration and has made a patch available to customers on request. CISA lists the affected sector as Transportation Systems, with deployment worldwide.

Why it matters

Hardcoded keys are a recurring failure mode in operational technology because they can’t be rotated the way a normal credential can — once exposed, every deployed unit sharing that key is affected until firmware is patched.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *