Vulnerabilities
Wärtsilä FOS‑Onboard Faces Dual Hard‑Coded Key Vulnerabilities (CVE‑2026‑78225, CVE‑2026‑81855)
Two critical CVEs expose hard‑coded cryptographic keys in Wärtsilä FOS‑Onboard 5.07.0923.01, allowing attackers to push unauthorized updates, execute code or steal credentials. With a CVSS score of 9.1, the flaws threaten transportation‑system operators worldwide. Wärtsilä has released a patch; users must contact the vendor to apply it immediately.
Wärtsilä’s FOS‑Onboard software, used across global transportation systems, now carries two high‑severity vulnerabilities that rely on hard‑coded cryptographic keys.
What’s at stake?
- CVE‑2026‑78225 – a server‑side key hard‑coding flaw in the deployer‑ng Update Controller.
- CVE‑2026‑81855 – a client‑side key hard‑coding flaw in the robot testing framework.
Both defects can be exploited to deliver rogue firmware, run arbitrary code or extract privileged credentials, effectively letting an attacker impersonate a legitimate client. The CVSS score of 9.1 classifies them as Critical.
Who’s affected?
Only version 5.07.0923.01 of FOS‑Onboard is known to be vulnerable. Operators of maritime, rail, or other transportation assets using this release should review their deployments.
Mitigation
Wärtsilä states the flaws are not exploitable when the product follows the recommended installation guidelines. Nonetheless, a security patch has been issued. Users are urged to obtain and install the update without delay. Contact Wärtsilä via the official patch deployment portal: https://www.wartsila.com/services-catalogue/engine-services-4-stroke/wartsila-ics-patch-deployment#contact.
"If your system is running the affected version, apply the patch immediately to eliminate the risk of unauthorized code execution or credential compromise." – Wärtsilä Security Advisory
Key takeaways
- Hard‑coded keys are a major security risk; always use dynamic key management.
- Patch promptly – even if the vendor says the issue is non‑exploitable in default configurations.
- Verify that your deployment aligns with the vendor’s recommended configuration to minimize exposure.