CVE-2026-78225: Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key
Published Sep 15, 2026
·Updated
A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.
Affected Software
1 affected component
Wärtsilä FOS-Onboard deployer-ng Update Controller
Event History
Sep 15, 2026
CVE Published
via MITRE·09:29 PM
Data Sourced
via MITRE·09:29 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The CVSS vector indicates that the attack is network-accessible and does not require prior privileges or user interaction. Exploitation has high attack complexity.
2
What is the potential impact if exploitation succeeds?
The rating indicates high potential impact to confidentiality, integrity, and availability, with a changed scope. The issue is rated critical with a score of 9.