# Wärtsilä FOS-Onboard hardcoded crypto keys found

Published: 2026-09-15 · Severity: routine · Sectors: transportation
Canonical: https://vorant.io/reports/56a22871-29dc-5ef3-b4f7-42d23107be2a/w-rtsil-fos-onboard-hardcoded-crypto-keys-found

> Hardcoded cryptographic keys in Wärtsilä FOS-Onboard could let attackers push unauthorized updates or impersonate privileged clients; no in-the-wild exploitation reported.

CISA published an ICS advisory for Wärtsilä FOS-Onboard version 5.07.0923.01, a maritime engine/vessel monitoring system deployed worldwide in the Transportation Systems sector. Two vulnerabilities were identified by Cydome Security Ltd: a hardcoded cryptographic server key in the deployer-ng Update Controller component (CVE-2026-78225) and a hardcoded cryptographic client authentication key in the robot testing framework component (CVE-2026-81855). Both are classified under CWE-321 (Use of Hard-coded Cryptographic Key).

Successful exploitation could allow an attacker to deliver an unauthorized software update, execute arbitrary code, or extract credentials enabling impersonation of a privileged client on affected FOS-Onboard installations. Wärtsilä states the vulnerabilities are not exploitable when the product is installed per recommended guidance, and has developed a security patch that affected users must obtain directly from the vendor via their ICS patch deployment contact channel.

CISA reports no known public exploitation targeting these vulnerabilities at this time. Standard ICS defense-in-depth mitigations apply: minimize internet exposure of control system devices, isolate ICS networks behind firewalls away from business networks, and use secure remote access methods such as up-to-date VPNs when remote connectivity is required. Organizations operating Wärtsilä FOS-Onboard should verify installation configuration against vendor recommendations and contact Wärtsilä to obtain the patch.

## Mentioned in this report

- Vulnerabilities: CVE-2026-78225, CVE-2026-81855

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-02

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/56a22871-29dc-5ef3-b4f7-42d23107be2a/w-rtsil-fos-onboard-hardcoded-crypto-keys-found.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
