← Back to Feed
Wärtsilä FOS-Onboard
CVE-2026-78225CVE-2026-81855
September 15, 2026 · CISA (US-CERT) · Severity: CRITICAL
Wärtsilä FOS-Onboard version 5.07.0923.01 is affected by multiple vulnerabilities that could allow an attacker to deliver unauthorized updates, execute arbitrary code, or extract credentials to impersonate a privileged client. The vulnerabilities involve the use of hard-coded cryptographic keys, with a CVSS v3 base score of 9.1. The affected product is deployed in transportation systems infrastructure worldwide. Wärtsilä has released guidance addressing these vulnerabilities and recommends that organizations apply the necessary updates.
Key Takeaways
- Wärtsilä FOS-Onboard 5.07.0923.01 contains hard-coded cryptographic key vulnerabilities rated CVSS 9.1, affecting transportation systems infrastructure worldwide.
- Attackers exploiting these flaws could deliver unauthorized software updates, execute arbitrary code, or extract credentials to impersonate privileged clients.
- The vulnerabilities affect onboard systems deployed globally, making timely patch application critical for transportation sector cybersecurity.