IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Wärtsilä FOS-Onboard

CRITICAL
CVSS 9.1
Date 2026-09-15T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client.

// Vulnerabilities (2)

CVE ID CVSS Score Severity Description
CVE-2026-81855 9.1 critical
A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard.
CVE-2026-78225 9.0 critical
A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.

// Remediations (1)

Mitigation: Wärtsilä states that the vulnerabilities are not exploitable when the product is installed as recomm
Wärtsilä states that the vulnerabilities are not exploitable when the product is installed as recommended, and has developed a security patch. Users are also directed to contact Wärtsilä to obtain and install the patch. To obtain and install the latest patch, contact Wärtsilä

// References