<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-78225 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-78225/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 16:31:51 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-78225/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Hard-coded Cryptographic Keys in Wärtsilä FOS-Onboard</title><link>https://feed.craftedsignal.io/briefs/2026-09-wartsila-fos-onboard/</link><pubDate>Tue, 15 Sep 2026 16:31:51 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-wartsila-fos-onboard/</guid><description>Wärtsilä FOS-Onboard version 5.07.0923.01 contains hard-coded cryptographic keys in the Update Controller and robot testing framework that could facilitate unauthorized code execution, update deployment, and credential theft.</description><content:encoded><![CDATA[<p>Wärtsilä has disclosed two critical vulnerabilities in the FOS-Onboard software, version 5.07.0923.01, related to the use of hard-coded cryptographic keys. The first vulnerability, CVE-2026-78225, affects the deployer-ng Update Controller component, while the second, CVE-2026-81855, impacts the robot testing framework. These flaws present a significant risk to maritime transportation systems, as they allow unauthenticated remote attackers to bypass security controls. By leveraging these hard-coded keys, an attacker could potentially sign and deliver malicious software updates, execute arbitrary code, or extract sensitive credentials required to impersonate privileged clients. The vulnerabilities were reported to CISA by Cydome Security Ltd. Given the nature of these assets in global transportation, rapid patching or implementation of strict network isolation is essential to prevent exploitation in critical infrastructure environments.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation could result in full system compromise, unauthorized persistent access, and the ability to manipulate maritime navigation or fleet management operations. These vulnerabilities impact the transportation sector globally. If exploited, an attacker could gain the ability to push malicious firmware or software updates to onboard systems, leading to severe operational disruption or safety risks. No known public exploitation has been reported as of September 2026.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Contact Wärtsilä directly to obtain and deploy the security patch for FOS-Onboard version 5.07.0923.01.</li>
<li>Isolate FOS-Onboard systems from the internet and business networks by placing them behind robust firewalls.</li>
<li>If remote access to the system is required, enforce the use of secure VPNs, ensuring that the VPN infrastructure itself is patched and hardened.</li>
<li>Conduct a risk assessment to determine the exposure of FOS-Onboard assets to unauthorized network segments.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>ics</category><category>transportation</category><category>patch-management</category><category>cve-2026-78225</category><category>cve-2026-81855</category></item></channel></rss>