Tec Nikan
فارسی
Talk to us
All news

Hard-Coded Keys Found in Wärtsilä's Shipboard Fleet Software

CISA advisory ICSA-26-258-02 flags two critical hard-coded cryptographic keys in Wärtsilä FOS-Onboard, both scoring above 9.0, and both sitting in components that ship with the product.

maritime OTICS advisoryhard-coded keysWärtsiläCISA

CISA released advisory ICSA-26-258-02 on 15 September covering two hard-coded cryptographic key flaws in Wärtsilä FOS-Onboard 5.07.0923.01, the Finnish marine supplier's onboard fleet optimisation software. Both are rated critical. CVE-2026-78225 sits in the deployer-ng update controller and scores 9.0 on CVSS v3.1 and 9.5 on v4.0. CVE-2026-81855 sits in the robot testing framework component, at 9.1 and 9.3 respectively.

Both fall under CWE-321, use of a hard-coded cryptographic key, and CISA's description of the impact is blunt: an attacker can deliver an unauthorised update, execute code, or extract credentials. The presence of a test framework in a shipped product is itself notable, since it means a component intended for development is carrying a key into production installations.

Wärtsilä's position is that the vulnerabilities are not exploitable when the product is installed as recommended. A patch exists but is not published for download; customers have to contact the vendor directly to arrange deployment. The issues were reported to CISA by Cydome Security, a maritime cybersecurity firm, and CISA says it has no reports of public exploitation targeting them.

The deployment sector is listed as Transportation Systems, which understates where this software sits. Fleet optimisation runs between bridge systems, engine automation and shore-side connectivity, and a hard-coded key in the update path turns the software's own patching channel into a way in. A ship also has none of the segmentation options a plant has — there is no separate corporate network to retreat behind, and the people who would apply a patch are at sea.

For anyone working to IACS UR E26 and E27 or the IMO cyber risk guidelines, this is the exact scenario those rules were written around: a supplier-provided component with an embedded secret, on a vessel, where remote support is the normal way work gets done.

Want to work with us?

Tell us what you're building and we'll help you scope the first deployment.