CVE-2026-81855 Details
Description
A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard.
A vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard, specifically in version 5.07.0923.01. This vulnerability involves a hardcoded cryptographic client authentication key, which could be exploited to deliver unauthorized updates, execute code, or extract credentials to impersonate a privileged client.
Wärtsilä has developed a security patch for this vulnerability. Users are advised to contact Wärtsilä to obtain and install the patch. For more information, visit the Wärtsilä ICS patch deployment service page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 15, 2026CISA-ADP
Assessed Sep 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-321 | Use of Hard-coded Cryptographic Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Wärtsilä FOS-Onboard | 5.07.0923.01 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | CVE Modified | [email protected] |
| Sep 16, 2026 | CVE Modified | CISA-ADP |
| Sep 15, 2026 | New CVE Received | [email protected] |
Volerion