Critical Hard‑coded Key Vulnerabilities (CVE‑2026‑78225, CVE‑2026‑81855) in Wärtsilä FOS‑Onboard Threaten Maritime Control Systems
What It Is – Two CVEs disclose a hard‑coded cryptographic server key in the deployer‑ng Update Controller component of Wärtsilä FOS‑Onboard (version 5.07.0923.01). The flaw enables an attacker to deliver unauthorized software updates, execute arbitrary code, or extract credentials to impersonate a privileged client.
Exploitability – CVSS v3.1 base score 9.1 (Critical). No public exploits are known, and Wärtsilä states the issue is not exploitable when the product is installed per the vendor’s recommended configuration. A security patch has been released.
Affected Products – Wärtsilä FOS‑Onboard 5.07.0923.01 (industrial‑control software used in transportation‑system vessels worldwide).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous monitoring of cryptographic controls and patch status across OT assets – a core control objective that satisfies multiple frameworks (e.g., NIST CSF 2.0 Identify and Protect).
- Provides concrete evidence that a hard‑coded key can undermine the integrity of update mechanisms, highlighting gaps in configuration‑management and change‑control processes.
- Enables organizations to prove due‑diligence to regulators and customers by documenting timely remediation and retaining verifiable audit trails.
Recommended Actions
- Obtain and apply Wärtsilä’s security patch immediately; verify the removal of the hard‑coded key.
- Update your asset inventory and configuration‑management database to reflect the patched version.
- Capture patch‑installation evidence in your control‑mapping repository to support audit readiness.
Source: CISA Advisory – ICSA‑26‑258‑02